<?xml version="1.0" encoding="UTF-8"?>
<oval_definitions xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#windows windows-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#independent independent-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5">
  <generator>
    <oval:product_name>The OVAL Repository</oval:product_name>
    <oval:schema_version>5.4</oval:schema_version>
    <oval:timestamp>2015-09-03T06:35:25.477-04:00</oval:timestamp>
  </generator>
  <definitions>
    <definition id="oval:org.mitre.oval:def:999" version="3" class="vulnerability">
      <metadata>
        <title>Hyperlink Object Buffer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference ref_id="CVE-2006-3086" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3086" source="CVE"/>
        <description>Stack-based buffer overflow in the HrShellOpenWithMonikerDisplayName function in Microsoft Hyperlink Object Library (hlink.dll) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long hyperlink, as demonstrated using an Excel worksheet with a long link in Unicode, aka "Hyperlink COM Object Buffer Overflow Vulnerability." NOTE: this is a different issue than CVE-2006-3059.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:41.883-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:50.665-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:999 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:05:39.471-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:49.509-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win2K,SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="The version of Hlink.dll is less than 5.2.3790.2748." test_ref="oval:org.mitre.oval:tst:180"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP1">
          <extend_definition comment="Microsoft Windows XP SP1 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          <criterion comment="The version of Hlink.dll is less than 5.2.3790.2748." test_ref="oval:org.mitre.oval:tst:180"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="The version of Hlink.dll is less than 5.2.3790.2748." test_ref="oval:org.mitre.oval:tst:180"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP1 (64-bit)">
          <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="The version of Hlink.dll is less than 5.2.3790.2748." test_ref="oval:org.mitre.oval:tst:180"/>
        </criteria>
        <criteria operator="AND" comment="S03-Gold">
          <extend_definition comment="Microsoft Windows Server 2003 (x86) Gold is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="The version of Hlink.dll is less than 5.2.3790.560." test_ref="oval:org.mitre.oval:tst:114"/>
        </criteria>
        <criteria operator="AND" comment="S03,SP1">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="The version of Hlink.dll is less than 5.2.3790.2748." test_ref="oval:org.mitre.oval:tst:180"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:995" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 COM Internet Services/RPC over HTTP Proxy Component Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>COM Internet Services</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0807" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0807"/>
        <description>Buffer overflow in the COM Internet Services and in the RPC over HTTP Proxy components for Microsoft Windows NT Server 4.0, NT 4.0 Terminal Server Edition, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service via a crafted request.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-25T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-06-18T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-02T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="the version of rpcproxy.dll is less than 5.0.2195.6904" negate="false" test_ref="oval:org.mitre.oval:tst:1346"/>
          <criterion comment="the patch kb828741 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1499"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="COM Internet Services are enabled" negate="false" test_ref="oval:org.mitre.oval:tst:1383"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:99" version="10" class="vulnerability">
      <metadata>
        <title>IE v6.0 Content Disposition/Type Arbitrary Code Execution</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0193" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0193"/>
        <description>Microsoft Internet Explorer 5.01 and 6.0 allow remote attackers to execute arbitrary code via malformed Content-Disposition and Content-Type header fields that cause the application for the spoofed file type to pass the file back to the operating system for handling rather than raise an error message, aka the first variant of the "Content Disposition" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-27T05:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2005-03-07T05:00:00.000-04:00" comment="modified wrt-222 - changed pattern match">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-03-09T05:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-29T05:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Changed IE registry test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-07-03T12:56:00.000-04:00" comment="Added negate=true attribute to criteria sub-block to fix conversion error from OVAL 4.2 to OVAL 5.0">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-07-03T12:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:41.221-04:00">ACCEPTED</status_change>
            <modified comment="Multiple corrections and update to POSIX compatibility for ste:2878" date="2010-11-29T16:13:00.904-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-11-29T16:14:04.414-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:01:44.339-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:44:58.502-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:03:39.939-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:59.421-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:29.049-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the version of mshtml.dll is less than 6.0.2716.2200" negate="false" test_ref="oval:org.mitre.oval:tst:3086"/>
        <criterion comment="the patch q321232 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3119"/>
        <criterion comment="the patch q323759 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3118"/>
        <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
        <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
        <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed" negate="true">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="SP4 or later Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3073"/>
        </criteria>
        <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:98" version="3" class="vulnerability">
      <metadata>
        <title>Gopher Client Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0371" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0371"/>
        <description>Buffer overflow in gopher client for Microsoft Internet Explorer 5.1 through 6.0, Proxy Server 2.0, or ISA Server 2000 allows remote attackers to execute arbitrary code via a gopher:// URL that redirects the user to a real or simulated gopher server that sends a long response.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T05:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Changed IE registry test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:59.278-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:28.963-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="File %windir%\system32\mshtml.dll version is less than 6.0.2719.2200" negate="false" test_ref="oval:org.mitre.oval:tst:2945"/>
          <criterion comment="the patch q323759 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3118"/>
          <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
          <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
          <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
          <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
          <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
          <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
          <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
          <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Gopher Enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2944"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:974" version="5" class="vulnerability">
      <metadata>
        <title>IE Frame Domain Verification Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0027" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0027"/>
        <description>Internet Explorer 5.5 and 6.0 allows remote attackers to read certain files and spoof the URL in the address bar by using the Document.open function to pass information between two frames from different domains, a new variant of the "Frame Domain Verification" vulnerability described in MS:MS01-058/CAN-2001-0874.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-29T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-05-25T04:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T04:00:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2004-09-22T04:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-09-22T04:01:00.000-04:00" comment="Replaced IE cumulative patch IDs to correspond to the original IDs">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2004-10-06T04:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Changed IE registry test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-09-20T04:04:00.000-04:00" comment="Changed IE registry test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:974 - extra operators were removed." date="2014-01-14T17:12:00.581-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-14T17:14:13.246-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:55.244-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
        <criterion comment="File %windir%\system32\mshtml.dll version is less than 6.0.2713.1100" test_ref="oval:org.mitre.oval:tst:1451"/>
        <criterion negate="true" comment="Patch Q316059.exe Installed" test_ref="oval:org.mitre.oval:tst:1458"/>
        <criterion negate="true" comment="Patch Q319282 Installed" test_ref="oval:org.mitre.oval:tst:1457"/>
        <criterion negate="true" comment="the patch q321232 is installed (Installed Components key)" test_ref="oval:org.mitre.oval:tst:3119"/>
        <criterion negate="true" comment="the patch q323759 is installed (Installed Components key)" test_ref="oval:org.mitre.oval:tst:3118"/>
        <criterion negate="true" comment="the patch q328970 is installed (Installed Components key)" test_ref="oval:org.mitre.oval:tst:3117"/>
        <criterion negate="true" comment="the patch q324929 is installed (Installed Components key)" test_ref="oval:org.mitre.oval:tst:3116"/>
        <criterion negate="true" comment="the patch q810847 is installed (Installed Components key)" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion negate="true" comment="the patch q813489 is installed (Installed Components key)" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion negate="true" comment="the patch q818529 is installed (Installed Components key)" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion negate="true" comment="the patch q822925 is installed (Installed Components key)" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion negate="true" comment="the patch q828750 is installed (Installed Components key)" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion negate="true" comment="the patch q824145 is installed (Installed Components key)" test_ref="oval:org.mitre.oval:tst:3110"/>
        <criterion negate="true" comment="the patch q832894 is installed (Installed Components key)" test_ref="oval:org.mitre.oval:tst:2588"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:965" version="9" class="vulnerability">
      <metadata>
        <title>IE6 Script Execution Vulnerability (Win2K/XP,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1190" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1190"/>
        <description>Microsoft Internet Explorer 5.01 through 6 does not always return the correct IOleClientSite information when dynamically creating an embedded object, which could cause Internet Explorer to run the object in the wrong security context or zone, and allow remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added an anchor to the regex used to check for Internet Explorer 6." date="2007-01-11T20:38:00.950-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-01-11T20:49:17.686-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:41:02.006-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:2185 - Anchored regular expression" date="2011-02-22T12:51:00.261-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:52:27.205-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:26.265-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:44:48.971-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:03:39.230-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:54.607-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:28.866-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Win2K or XP,SP1 is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="Internet Explorer 6 (any patch level) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2333"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2800.1543" negate="false" test_ref="oval:org.mitre.oval:tst:2332"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:963" version="4" class="vulnerability">
      <metadata>
        <title>IE File Upload Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0114" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0114"/>
        <description>The file upload control in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to automatically upload files from the local system via a web page containing a script to upload the files.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2004-09-22T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-09-22T11:10:00.000-04:00" comment="Replaced IE cumulative patch IDs to correspond to the original IDs">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2004-10-06T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:56.449-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:28.786-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
        <criterion comment="the version of mshtml.dll is less than 5.50.4926.2500" negate="false" test_ref="oval:org.mitre.oval:tst:1454"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:961" version="2" class="vulnerability" deprecated="true">
      <metadata>
        <title>Microsoft Data Access Components SQL-DMO Buffer Overflow (Test 1)</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Data Access Components 2.5</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0353" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0353"/>
        <description>Buffer overflow in a component of SQL-DMO for Microsoft Data Access Components (MDAC) 2.5 through 2.7 allows remote attackers to execute arbitrary code via a long response to a broadcast request to UDP port 1434.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-04T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-02-28T12:00:00.000-04:00" comment="split out the MDAC and file version tests from the compound test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-03-02T08:52:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-23T08:09:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Deprecating duplicate definition for CVE-2003-0353" date="2010-05-05T12:00:00.000-05:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2010-05-05T12:00:00.000-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Microsoft Data Access Components 2.5 is installed" test_ref="oval:org.mitre.oval:tst:2576"/>
        <criterion comment="File %windir%\System32\odbcbcp.dll is less than 3.70.11.40" test_ref="oval:org.mitre.oval:tst:1396"/>
        <criterion comment="Patch Q823718 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1395"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:96" version="4" class="vulnerability">
      <metadata>
        <title>IE Cookie-based Script Execution</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0078" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0078"/>
        <description>The zone determination function in Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to run scripts in the Local Computer zone by embedding the script in a cookie, aka the "Cookie-based Script Execution" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T05:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-03-04T05:00:00.000-04:00" comment="Added the configuration check to see if cookies are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T05:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T05:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="modified wrt-18 - Changed value element to include pattern match">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:59.093-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:28.687-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2715.400" negate="false" test_ref="oval:org.mitre.oval:tst:2952"/>
          <criterion comment="the patch q319282 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3120"/>
          <criterion comment="the patch q321232 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3119"/>
          <criterion comment="the patch q323759 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3118"/>
          <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
          <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
          <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
          <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
          <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
          <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
          <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="cookies are enabled">
            <criteria operator="AND" comment="current user settings are being used and cookies are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="persistent cookies that are stored on your computer are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2950"/>
              <criterion comment="persistent cookies that are stored on your computer are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2949"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and cookies are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="per-session cookies (not stored) are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2948"/>
              <criterion comment="per-session cookies (not stored) are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2947"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:959" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 WMF/EMF Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Enhanced Metafile (EMF)</product>
          <product>Windows Metafile (WMF)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0906" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0906"/>
        <description>Buffer overflow in the rendering for (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1 allows remote attackers to execute arbitrary code via a malformed WMF or EMF image.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="the version of mf3216.dll is less than 5.0.2195.6898" negate="false" test_ref="oval:org.mitre.oval:tst:1398"/>
        <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:955" version="6" class="vulnerability">
      <metadata>
        <title>Windows 2000 RPCSS Service DCOM Activation Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Remote Procedure Call (RPC)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0116" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0116"/>
        <description>An Activation function in the RPCSS Service involved with DCOM activation for Microsoft Windows 2000, XP, and 2003 allows remote attackers to cause a denial of service (memory consumption) via an activation request with a large length field.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Multiple corrections and update to POSIX compatibility for ste:2884" date="2010-11-29T16:14:00.692-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-11-29T16:14:39.871-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:01:43.660-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:44:46.591-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:03:37.564-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="the version of rpcss.dll is less than 5.0.2195.6906" negate="false" test_ref="oval:org.mitre.oval:tst:1407"/>
          <criterion comment="the patch kb828741 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1499"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="DCOM is enabled on systems with SP3 or later">
            <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3079"/>
            <criterion comment="DCOM is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2913"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:951" version="2" class="vulnerability">
      <metadata>
        <title>Windows 2000 SSL PCT Handshake Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Private Communications Transport (PCT)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0719" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0719"/>
        <description>Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as used in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via PCT 1.0 handshake packets.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected to use a forward slash as the separator in the key." date="2007-05-07T15:59:00.528-04:00">
              <contributor organization="Secure Elements, Inc.">Glenn Strickland</contributor>
            </modified>
            <status_change date="2007-05-07T16:06:47.903-04:00">INTERIM</status_change>
            <status_change date="2007-05-23T15:05:55.915-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="the version of schannel.dll is less than 5.1.2195.6899" negate="false" test_ref="oval:org.mitre.oval:tst:1501"/>
          <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="SSL is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:1508"/>
          <criterion comment="PCT support is disabled" negate="true" test_ref="oval:org.mitre.oval:tst:1503"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:95" version="7" class="vulnerability" deprecated="true">
      <metadata>
        <title>DEPRECATED: Windows 2000 IIS ASP Server-Side Include Function Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0149" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0149"/>
        <description>Buffer overflow in ASP Server-Side Include Function in IIS 4.0, 5.0 and 5.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via long file names.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected to use a forward slash as the separator in the key." date="2007-05-07T15:59:00.430-04:00">
              <contributor organization="Secure Elements, Inc.">Glenn Strickland</contributor>
            </modified>
            <status_change date="2007-05-07T16:06:11.689-04:00">INTERIM</status_change>
            <status_change date="2007-05-23T15:05:55.660-04:00">ACCEPTED</status_change>
            <modified comment="Multiple corrections and update to POSIX compatibility for ste:2884" date="2010-11-29T16:14:00.692-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-11-29T16:14:39.392-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:01:42.893-05:00">ACCEPTED</status_change>
            <modified comment="Use def:12407 instead" date="2011-01-20T10:08:21.606-05:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-01-20T10:08:21.606-05:00">DEPRECATED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
          <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
          <criterion comment="the version of w3svc.dll is less than 5.0.2195.5269" negate="false" test_ref="oval:org.mitre.oval:tst:3080"/>
          <criterion comment="Patch Q319733 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3095"/>
          <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
          <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
          <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3079"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="asp.dll mapping exists" negate="false" test_ref="oval:org.mitre.oval:tst:3092"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:948" version="4" class="vulnerability">
      <metadata>
        <title>IE File Download Dialog Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0309" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0309"/>
        <description>Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to bypass security zone restrictions and execute arbitrary programs via a web document with a large number of duplicate file:// or other requests that point to the program and open multiple file download dialogs, which eventually cause Internet Explorer to execute the program, as demonstrated using a large number of FRAME or IFRAME tags, aka the "File Download Dialog Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-29T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2004-09-22T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-09-22T11:10:00.000-04:00" comment="Replaced IE cumulative patch IDs to correspond to the original IDs">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2004-10-06T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:51.242-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:28.466-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
        <criterion comment="the version of mshtml.dll is less than 5.50.4926.2500" negate="false" test_ref="oval:org.mitre.oval:tst:1454"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:942" version="2" class="vulnerability">
      <metadata>
        <title>Windows 2000 IIS Cross-site Scripting Vulnerabilities</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1181" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1181"/>
        <description>Multiple cross-site scripting (XSS) vulnerabilities in the administrative web pages for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allow remote attackers to execute HTML script as other users through (1) a certain ASP file in the IISHELP virtual directory, or (2) possibly other unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-01-11T12:00:00.000-04:00" comment="modified wft-330 - changed the version of msw3prt.dll to test against from 5.5.2195.58075 to 5.0.2195.5807">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-01-20T01:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="File %windir%\System32\msw3prt.dll is less than 5.0.2195.5807" negate="false" test_ref="oval:org.mitre.oval:tst:1447"/>
        <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
        <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:938" version="1" class="vulnerability">
      <metadata>
        <title>IIS5.0 Windows Media Services Large POST Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0349" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0349"/>
        <description>Buffer overflow in the streaming media component for logging multicast requests in the ISAPI for the logging capability of Microsoft Windows Media Services (nsiislog.dll), as installed in IIS 5.0, allows remote attackers to execute arbitrary code via a large POST request to nsiislog.dll.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="File %windir%\System32\nsiislog.dll is less than 4.1.0.3932" negate="false" test_ref="oval:org.mitre.oval:tst:1437"/>
        <criterion comment="Patch KB822343 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1438"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:936" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 Media Services ISAPI Logging Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0227" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0227"/>
        <description>The logging capability for unicast and multicast transmissions in the ISAPI extension for Microsoft Windows Media Services in Microsoft Windows NT 4.0 and 2000, nsiislog.dll, allows remote attackers to cause a denial of service in Internet Information Server (IIS) and execute arbitrary code via a certain network request.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="File %windir%\System32\nsiislog.dll is less than 4.1.0.3931" negate="false" test_ref="oval:org.mitre.oval:tst:1440"/>
        <criterion comment="Patch KB817772 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1439"/>
        <criterion comment="Patch KB822343 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1438"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:933" version="3" class="vulnerability">
      <metadata>
        <title>IIS WebDAV Request Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0226" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0226"/>
        <description>Microsoft Internet Information Services (IIS) 5.0 and 5.1 allows remote attackers to cause a denial of service via a long WebDAV request with a (1) PROPFIND or (2) SEARCH method, which generates an error condition that is not properly handled.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-27T10:43:00.000-04:00" comment="modified wft-332 - Changed test to match comment">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Changed tst:1444 to use obj:496 was introduced to properly look for w3svc.dll in System32/inetsrv." date="2007-07-18T12:59:00.963-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-07-18T13:02:05.118-04:00">INTERIM</status_change>
            <status_change date="2007-08-02T14:47:16.660-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="File %windir%\System32\w3svc.dll is less than 5.0.2195.6672" negate="false" test_ref="oval:org.mitre.oval:tst:1444"/>
        <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1443"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:931" version="2" class="vulnerability">
      <metadata>
        <title>IIS5.0 Script Source Access Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1180" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1180"/>
        <description>A typographical error in the script source access permissions for Internet Information Server (IIS) 5.0 does not properly exclude .COM files, which allows attackers with only write permissions to upload malicious .COM files, aka "Script Source Access Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-01-11T12:00:00.000-04:00" comment="modified wft-330 - changed the version of msw3prt.dll to test against from 5.5.2195.58075 to 5.0.2195.5807">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-01-20T01:08:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="File %windir%\System32\msw3prt.dll is less than 5.0.2195.5807" negate="false" test_ref="oval:org.mitre.oval:tst:1447"/>
        <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
        <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:930" version="2" class="vulnerability">
      <metadata>
        <title>Windows 2000 IIS Out of Process Privilege Elevation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0869" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0869"/>
        <description>Unknown vulnerability in the hosting process (dllhost.exe) for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allows remote attackers to gain privileges by executing an out of process application that acquires LocalSystem privileges, aka "Out of Process Privilege Elevation."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-01-11T12:00:00.000-04:00" comment="modified wft-330 - changed the version of msw3prt.dll to test against from 5.5.2195.58075 to 5.0.2195.5807">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-01-20T01:08:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="File %windir%\System32\msw3prt.dll is less than 5.0.2195.5807" negate="false" test_ref="oval:org.mitre.oval:tst:1447"/>
        <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
        <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:927" version="4" class="vulnerability">
      <metadata>
        <title>IIS5.0 Specialized Header Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2000-0778" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0778"/>
        <description>IIS 5.0 allows remote attackers to obtain source code for .ASP files and other scripts via an HTTP GET request with a "Translate: f" header, aka the "Specialized Header" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-04T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:44:36.452-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:03:36.873-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:926" version="4" class="vulnerability">
      <metadata>
        <title>IE URLMON Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0113" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0113"/>
        <description>Buffer overflow in URLMON.DLL in Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code via an HTTP response containing long values in (1) Content-type and (2) Content-encoding fields.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2004-09-22T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-09-22T11:10:00.000-04:00" comment="Replaced IE cumulative patch IDs to correspond to the original IDs">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2004-10-06T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:46.767-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:28.315-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
        <criterion comment="the version of mshtml.dll is less than 5.50.4926.2500" negate="false" test_ref="oval:org.mitre.oval:tst:1454"/>
        <criterion comment="File %windir%\system32\urlmon.dll version is less than 5.50.4927.2100" negate="false" test_ref="oval:org.mitre.oval:tst:1449"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:925" version="5" class="vulnerability">
      <metadata>
        <title>MS IE HTML Directive Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0022" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0022"/>
        <description>Buffer overflow in the implementation of an HTML directive in mshtml.dll in Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code via a web page that specifies embedded ActiveX controls in a way that causes 2 Unicode strings to be concatenated.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-29T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-05-25T04:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T04:00:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2004-09-22T04:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-09-22T04:01:00.000-04:00" comment="Replaced IE cumulative patch IDs to correspond to the original IDs">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2004-10-06T04:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Changed IE registry test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:925 - extra operators were removed." date="2014-01-14T17:12:00.581-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-14T17:14:13.577-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:55.111-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
        <criterion comment="File %windir%\system32\mshtml.dll version is less than 6.0.2713.1100" test_ref="oval:org.mitre.oval:tst:1451"/>
        <criterion negate="true" comment="Patch Q316059.exe Installed" test_ref="oval:org.mitre.oval:tst:1458"/>
        <criterion negate="true" comment="Patch Q319282 Installed" test_ref="oval:org.mitre.oval:tst:1457"/>
        <criterion negate="true" comment="the patch q321232 is installed (Installed Components key)" test_ref="oval:org.mitre.oval:tst:3119"/>
        <criterion negate="true" comment="the patch q323759 is installed (Installed Components key)" test_ref="oval:org.mitre.oval:tst:3118"/>
        <criterion negate="true" comment="the patch q328970 is installed (Installed Components key)" test_ref="oval:org.mitre.oval:tst:3117"/>
        <criterion negate="true" comment="the patch q324929 is installed (Installed Components key)" test_ref="oval:org.mitre.oval:tst:3116"/>
        <criterion negate="true" comment="the patch q810847 is installed (Installed Components key)" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion negate="true" comment="the patch q813489 is installed (Installed Components key)" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion negate="true" comment="the patch q818529 is installed (Installed Components key)" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion negate="true" comment="the patch q822925 is installed (Installed Components key)" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion negate="true" comment="the patch q828750 is installed (Installed Components key)" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion negate="true" comment="the patch q824145 is installed (Installed Components key)" test_ref="oval:org.mitre.oval:tst:3110"/>
        <criterion negate="true" comment="the patch q832894 is installed (Installed Components key)" test_ref="oval:org.mitre.oval:tst:2588"/>
        <criterion comment="Use Machine Settings" test_ref="oval:org.mitre.oval:tst:1456"/>
        <criterion comment="Run ActiveX Controls and Plugins Allowed In At Least One Zone" test_ref="oval:org.mitre.oval:tst:1450"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:923" version="5" class="vulnerability">
      <metadata>
        <title>Zone Spoofing through Malformed Web Page Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0190" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0190"/>
        <description>Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code under fewer security restrictions via a malformed web page that requires NetBIOS connectivity, aka "Zone Spoofing through Malformed Web Page" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-30T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-05-25T04:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T04:00:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2004-09-22T04:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-09-22T04:01:00.000-04:00" comment="Replaced IE cumulative patch IDs to correspond to the original IDs">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2004-10-06T04:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Changed IE registry test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:923 - extra operators were removed." date="2014-01-14T17:12:00.581-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-14T17:14:13.411-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:54.970-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="File %windir%\system32\mshtml.dll version is less than 6.0.2716.2200" test_ref="oval:org.mitre.oval:tst:1453"/>
        <criterion negate="true" comment="the patch q321232 is installed (Installed Components key)" test_ref="oval:org.mitre.oval:tst:3119"/>
        <criterion negate="true" comment="the patch q323759 is installed (Installed Components key)" test_ref="oval:org.mitre.oval:tst:3118"/>
        <criterion negate="true" comment="the patch q328970 is installed (Installed Components key)" test_ref="oval:org.mitre.oval:tst:3117"/>
        <criterion negate="true" comment="the patch q324929 is installed (Installed Components key)" test_ref="oval:org.mitre.oval:tst:3116"/>
        <criterion negate="true" comment="the patch q810847 is installed (Installed Components key)" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion negate="true" comment="the patch q813489 is installed (Installed Components key)" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion negate="true" comment="the patch q818529 is installed (Installed Components key)" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion negate="true" comment="the patch q822925 is installed (Installed Components key)" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion negate="true" comment="the patch q828750 is installed (Installed Components key)" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion negate="true" comment="the patch q824145 is installed (Installed Components key)" test_ref="oval:org.mitre.oval:tst:3110"/>
        <criterion negate="true" comment="the patch q832894 is installed (Installed Components key)" test_ref="oval:org.mitre.oval:tst:2588"/>
        <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:922" version="4" class="vulnerability">
      <metadata>
        <title>IE Slash Characters in Type Property Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0344" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0344"/>
        <description>Buffer overflow in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to execute arbitrary code via / (slash) characters in the Type property of an Object tag in a web page.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-29T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2004-09-22T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-09-22T11:10:00.000-04:00" comment="Replaced IE cumulative patch IDs to correspond to the original IDs">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2004-10-06T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:46.507-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:28.218-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
        <criterion comment="the version of mshtml.dll is less than 5.50.4926.2500" negate="false" test_ref="oval:org.mitre.oval:tst:1454"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:921" version="5" class="vulnerability">
      <metadata>
        <title>IE File Execution User-prompt Bypass Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0727" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0727"/>
        <description>Internet Explorer 6.0 allows remote attackers to execute arbitrary code by modifying the Content-Disposition and Content-Type header fields in a way that causes Internet Explorer to believe that the file is safe to open without prompting the user, aka the "File Execution Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-29T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-05-25T04:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T04:00:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2004-09-22T04:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-09-22T04:01:00.000-04:00" comment="Replaced IE cumulative patch IDs to correspond to the original IDs">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2004-10-06T04:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Changed IE registry test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:921 - extra operators were removed." date="2014-01-14T17:12:00.581-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-14T17:14:13.076-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:54.738-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2712.0300" test_ref="oval:org.mitre.oval:tst:1460"/>
        <criterion negate="true" comment="Patch Q313675 Installed" test_ref="oval:org.mitre.oval:tst:1459"/>
        <criterion negate="true" comment="Patch Q316059.exe Installed" test_ref="oval:org.mitre.oval:tst:1458"/>
        <criterion negate="true" comment="Patch Q319282 Installed" test_ref="oval:org.mitre.oval:tst:1457"/>
        <criterion negate="true" comment="the patch q321232 is installed (Installed Components key)" test_ref="oval:org.mitre.oval:tst:3119"/>
        <criterion negate="true" comment="the patch q323759 is installed (Installed Components key)" test_ref="oval:org.mitre.oval:tst:3118"/>
        <criterion negate="true" comment="the patch q328970 is installed (Installed Components key)" test_ref="oval:org.mitre.oval:tst:3117"/>
        <criterion negate="true" comment="the patch q324929 is installed (Installed Components key)" test_ref="oval:org.mitre.oval:tst:3116"/>
        <criterion negate="true" comment="the patch q810847 is installed (Installed Components key)" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion negate="true" comment="the patch q813489 is installed (Installed Components key)" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion negate="true" comment="the patch q818529 is installed (Installed Components key)" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion negate="true" comment="the patch q822925 is installed (Installed Components key)" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion negate="true" comment="the patch q828750 is installed (Installed Components key)" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion negate="true" comment="the patch q824145 is installed (Installed Components key)" test_ref="oval:org.mitre.oval:tst:3110"/>
        <criterion negate="true" comment="the patch q832894 is installed (Installed Components key)" test_ref="oval:org.mitre.oval:tst:2588"/>
        <criterion comment="Use Machine Settings" test_ref="oval:org.mitre.oval:tst:1456"/>
        <criterion comment="File Downloads Allowed In At Least One Zone" test_ref="oval:org.mitre.oval:tst:1455"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:920" version="3" class="vulnerability">
      <metadata>
        <title>IE Cached Content Command Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0002" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0002"/>
        <description>Internet Explorer 5.5 and earlier allows remote attackers to obtain the physical location of cached content and open the content in the Local Computer Zone, then use compiled HTML help (.chm) files to execute arbitrary programs.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-29T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:47.240-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:28.132-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Internet Explorer 5.5 Installed">
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1466"/>
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1465"/>
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1464"/>
        </criteria>
        <criterion comment="File %windir%\system32\mshtml.dll version is less than 5.50.4613.1700" negate="false" test_ref="oval:org.mitre.oval:tst:1463"/>
        <criterion comment="Patch Q286045 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1462"/>
        <criterion comment="Patch Q295106 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1461"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:92" version="6" class="vulnerability" deprecated="true">
      <metadata>
        <title>DEPRECATED: Windows 2000 IIS HTTP Error Page Cross-site Scripting</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0148" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0148"/>
        <description>Cross-site scripting vulnerability in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other users via an HTTP error page.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <modified comment="Multiple corrections and update to POSIX compatibility for ste:2884" date="2010-11-29T16:14:00.692-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-11-29T16:14:39.293-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:01:42.201-05:00">ACCEPTED</status_change>
            <modified comment="Use def:12008 instead" date="2011-01-20T10:16:30.798-05:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-01-20T10:16:30.798-05:00">DEPRECATED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="the version of w3svc.dll is less than 5.0.2195.5269" negate="false" test_ref="oval:org.mitre.oval:tst:3080"/>
        <criterion comment="Patch Q319733 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3095"/>
        <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
        <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
        <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3079"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:912" version="2" class="vulnerability">
      <metadata>
        <title>Windows 2000 IIS System File Listing Privilege Elevation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0507" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0507"/>
        <description>IIS 5.0 uses relative paths to find system files that will run in-process, which allows local users to gain privileges via a Trojan horse file, aka the "System file listing privilege elevation" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-04T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-01-11T12:00:00.000-04:00" comment="modified wft-305 - changed the version of msw3prt.dll to test against from 5.5.2195.3649 to 5.0.2195.3649">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-01-20T01:05:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="File %windir%\System32\Msw3prt.dll is less than 5.0.2195.3649" negate="false" test_ref="oval:org.mitre.oval:tst:1471"/>
        <criterion comment="Patch Q301625 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3037"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:908" class="vulnerability" deprecated="true" version="2">
      <metadata>
        <title>Microsoft Client Service for NetWare Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4691" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4691"/>
        <description>Stack-based buffer overflow in the NetpManageIPCConnect function in the Workstation service (wkssvc.dll) in Microsoft Windows 2000 SP4 and XP SP2 allows remote attackers to execute arbitrary code via NetrJoinDomain2 RPC messages with a long hostname.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-11-15T12:28:05">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-11-17T12:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:54:02.185-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:41:01.806-05:00">ACCEPTED</status_change>
            <modified date="2007-05-08T07:29:32.570-04:00" comment="Deprecated becased this definition is a duplicate of oval:org.mitre.oval:def:607">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-05-08T07:29:32.570-04:00">DEPRECATED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:1448 - Correction of a filename (Spwmp.dll is replaced by wkssvc.dll as per the bulletin info.) in an object oval:org.mitre.oval:obj:1448 along with comments" date="2011-09-14T12:12:00.927-04:00">
              <contributor organization="SecPod Technologies">Pradeep R B</contributor>
            </modified>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Win2K,SP4" operator="AND">
          <extend_definition comment="Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of wkssvc.dll is less than 5.0.2195.7108" test_ref="oval:org.mitre.oval:tst:73"/>
        </criteria>
        <criteria comment="WinXP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of wkssvc.dll is less than 5.1.2600.2976" test_ref="oval:org.mitre.oval:tst:113"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:907" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 H.323 Protocol Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>H.323</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0117" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0117"/>
        <description>Unknown vulnerability in the H.323 protocol implementation in Windows 98, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="the version of h323.tsp is less than 5.0.2195.6901" negate="false" test_ref="oval:org.mitre.oval:tst:1475"/>
        <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:90" version="5" class="vulnerability">
      <metadata>
        <title>IIS Denial of Service via WebDAV</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0151" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0151"/>
        <description>IIS 5.0 allows remote attackers to cause a denial of service via a series of malformed WebDAV requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-10-20T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-10-20T10:07:00.000-04:00" comment="corrected configuration criterion">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2004-11-03T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Updated comment to include Vista and Server 2008" date="2009-05-07T10:32:00.713-04:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2009-05-07T10:34:05.420-04:00">INTERIM</status_change>
            <status_change date="2009-05-25T04:02:14.658-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:44:50.479-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:03:34.574-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Software section">
          <criterion comment="IIS major version equals 5" test_ref="oval:org.mitre.oval:tst:3081"/>
          <criterion comment="IIS minor version equals 0" test_ref="oval:org.mitre.oval:tst:3098"/>
          <criterion comment="File %windir%\system32\inetsrv\httpext.dll version is less than 0.9.3940.20" test_ref="oval:org.mitre.oval:tst:2955"/>
          <criterion negate="true" comment="Patch Q291845 Installed" test_ref="oval:org.mitre.oval:tst:2954"/>
          <criterion negate="true" comment="Patch Q293826 Installed" test_ref="oval:org.mitre.oval:tst:3020"/>
          <criterion negate="true" comment="Patch Q301625 Installed" test_ref="oval:org.mitre.oval:tst:3037"/>
          <criterion negate="true" comment="Patch Q319733 Installed" test_ref="oval:org.mitre.oval:tst:3095"/>
          <criterion negate="true" comment="Patch Q327696 Installed" test_ref="oval:org.mitre.oval:tst:3094"/>
          <criterion negate="true" comment="Patch Q811114 Installed" test_ref="oval:org.mitre.oval:tst:3093"/>
          <criterion negate="true" comment="Win2K/XP/2003/Vista/2008 Service Pack 2 is installed" test_ref="oval:org.mitre.oval:tst:3019"/>
        </criteria>
        <criteria operator="AND" comment="Configuration section">
          <criterion negate="true" comment="WebDav is disabled(for iis 5.0)" test_ref="oval:org.mitre.oval:tst:2953"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:896" version="3" class="vulnerability">
      <metadata>
        <title>Windows 2000 winlogon Remote Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows logon process (winlogon)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0806" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0806"/>
        <description>Buffer overflow in the Windows logon process (winlogon) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1, when a member of a domain, allows remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T10:54:00.000-04:00" comment="modified wft-133 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-09-23T19:48:00.000-04:00" comment="fixed  tst:1493 by changing referrence to obj:862 (msgina.dll) instead of obj:958 (msjet40.dll).">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <modified date="2006-09-23T20:21:00.000-04:00" comment="Replaced use of  tst:3085 to test for Windows 2000 with extended inventory definition def:85.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-09-23T21:48:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-10T20:40:01.140-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <extend_definition comment="Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <criterion comment="the version of msgina.dll is less than 5.0.2195.6895" negate="false" test_ref="oval:org.mitre.oval:tst:1493"/>
          <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="machine is a member of a domain" negate="false" test_ref="oval:org.mitre.oval:tst:1494"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:893" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 RPCSS DCOM Buffer Overflow (Blaster, Test 3)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Remote Procedure Call (RPC)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0813" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0813"/>
        <description>A multi-threaded race condition in the Windows RPC DCOM functionality with the MS03-039 patch installed allows remote attackers to cause a denial of service (crash or reboot) by causing two threads to process the same RPC request, which causes one thread to use memory after it has been freed, a different vulnerability than CVE-2003-0352 (Blaster/Nachi), CVE-2003-0715, and CVE-2003-0528, and as demonstrated by certain exploits against those vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="the version of rpcrt4.dll is less than 5.0.2195.6904" negate="false" test_ref="oval:org.mitre.oval:tst:1500"/>
        <criterion comment="the patch kb828741 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1499"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:892" version="2" class="vulnerability">
      <metadata>
        <title>Windows 2000 SSL Library Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Secure Sockets Layer (SSL)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0120" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0120"/>
        <description>The Microsoft Secure Sockets Layer (SSL) library, as used in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service via malformed SSL messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected to use a forward slash as the separator in the key." date="2007-05-07T15:59:00.528-04:00">
              <contributor organization="Secure Elements, Inc.">Glenn Strickland</contributor>
            </modified>
            <status_change date="2007-05-07T16:06:48.669-04:00">INTERIM</status_change>
            <status_change date="2007-05-23T15:05:54.714-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="the version of schannel.dll is less than 5.1.2195.6899" negate="false" test_ref="oval:org.mitre.oval:tst:1501"/>
          <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="SSL is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:1508"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:890" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 Local Descriptor Table Kernel Access Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Local Descriptor Table (LDT)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0910" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0910"/>
        <description>The NtSetLdtEntries function in the programming interface for the Local Descriptor Table (LDT) in Windows NT 4.0 and Windows 2000 allows local attackers to gain access to kernel memory and execute arbitrary code via an expand-down data segment descriptor descriptor that points to protected memory.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="the version of wintrust.dll is less than 5.131.2195.6824" negate="false" test_ref="oval:org.mitre.oval:tst:1502"/>
        <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:89" version="6" class="vulnerability">
      <metadata>
        <title>Windows 2000 MUP UNC Request Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Multiple UNC Provider (MUP)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0151" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0151"/>
        <description>Buffer overflow in Multiple UNC Provider (MUP) in Microsoft Windows operating systems allows local users to cause a denial of service or possibly gain SYSTEM privileges via a long UNC request.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-05-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified comment="Multiple corrections and update to POSIX compatibility for ste:2884" date="2010-11-29T16:14:00.692-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-11-29T16:14:38.663-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:01:40.909-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:44:50.245-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:03:33.870-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="File %windir%\system32\drivers\mup.sys version is less than 5.0.2195.5080" negate="false" test_ref="oval:org.mitre.oval:tst:2957"/>
        <criterion comment="Patch Q311967 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2956"/>
        <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3079"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:888" version="5" class="vulnerability">
      <metadata>
        <title>IE5.01,SP4 Web Folder Behaviors Cross-Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1989" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1989"/>
        <description>Unknown vulnerability in Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to obtain information and possibly execute code when browsing from a web site to a web folder view using WebDAV, aka "Web Folder Behaviors Cross-Domain Vulnerability".</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-23T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-08-25T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed reference to patch kb896727 from criteria.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed ste:2614: set datatype to version.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:54:00.319-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:59:44.943-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:41:01.509-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:36.936-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:28.047-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3831.1800" negate="false" test_ref="oval:org.mitre.oval:tst:2664"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:883" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 LSASS Buffer Overflow (Sasser Worm Vulnerability)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Local Security Authority Subsystem Service (LSASS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0533" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0533"/>
        <description>Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via a packet that causes the DsRolerUpgradeDownlevelServer function to create long debug entries for the DCPROMO.LOG log file, as exploited by the Sasser worm.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="the version of lsasrv.dll is less than 5.0.2195.6902" negate="false" test_ref="oval:org.mitre.oval:tst:1511"/>
        <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:882" version="1" class="vulnerability">
      <metadata>
        <title>Microsoft Outlook Express v5.5,SP2 MHTML URL Processing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Outlook Express</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0380" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0380"/>
        <description>The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through Outlook Express 6 SP1 allows remote attackers to bypass domain restrictions and execute arbitrary code, as demonstrated on Internet Explorer using script in a compiled help (CHM) file that references the InfoTech Storage (ITS) protocol handlers such as (1) ms-its, (2) ms-itss, (3) its, or (4) mk:@MSITStore, aka the "MHTML URL Processing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Microsoft Outlook Express 5.5 SP2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1514"/>
        <criterion comment="the version of inetcomm.dll is less than 5.50.4939.300" negate="false" test_ref="oval:org.mitre.oval:tst:1513"/>
        <criterion comment="the patch kb837009 is installed (installed components key)" negate="true" test_ref="oval:org.mitre.oval:tst:1512"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8654" version="1" class="vulnerability" deprecated="true">
      <metadata>
        <title>Remote Code Execution vulnerability in VBScript</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0483" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0483"/>
        <description>vbscript.dll in VBScript 5.1, 5.6, 5.7, and 5.8 in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, when Internet Explorer is used, allows user-assisted remote attackers to execute arbitrary code by referencing a (1) local pathname, (2) UNC share pathname, or (3) WebDAV server with a crafted .hlp file in the fourth argument (aka helpfile argument) to the MsgBox function, leading to code execution involving winhlp32.exe when the F1 key is pressed, aka "VBScript Help Keypress Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-02T10:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-03-02T18:45:20.448-05:00">DRAFT</status_change>
            <status_change date="2010-03-22T04:00:20.915-04:00">INTERIM</status_change>
            <modified comment="Deprecated duplicate definition def:8654, use def:7170 instead" date="2010-04-20T12:00:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2010-04-20T12:00:00.000-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
          <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8554" version="6" class="vulnerability">
      <metadata>
        <title>Uninitialized Memory Corruption Vulnerability (CVE-2010-0267)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0267" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0267"/>
        <description>Microsoft Internet Explorer 6, 6 SP1, and 7 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-30T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-03-31T14:15:19.540-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:36.652-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:21.690-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:25:07.813-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:28.072-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8554 - extended definitions of OS are without SP checks" date="2014-07-28T17:36:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:37:57.126-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:37.622-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 6 on Windows 2000 - RTMGDR">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1646" test_ref="oval:org.mitre.oval:tst:21144"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3676" test_ref="oval:org.mitre.oval:tst:20926"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5945" test_ref="oval:org.mitre.oval:tst:21222"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x64, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4672" test_ref="oval:org.mitre.oval:tst:20919"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on XP x86/x64 - GDR">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.17023" test_ref="oval:org.mitre.oval:tst:21218"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on XP x86/x64 - QFE">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21228" test_ref="oval:org.mitre.oval:tst:21283"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Server 2003 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.17023" test_ref="oval:org.mitre.oval:tst:21218"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Server 2003 x86/x64/ia64 - QFE">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21228" test_ref="oval:org.mitre.oval:tst:21283"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.17037" test_ref="oval:org.mitre.oval:tst:20820"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21242" test_ref="oval:org.mitre.oval:tst:21271"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.16000" test_ref="oval:org.mitre.oval:tst:9444"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.18444" test_ref="oval:org.mitre.oval:tst:20823"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.22653" test_ref="oval:org.mitre.oval:tst:21215"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.18000" test_ref="oval:org.mitre.oval:tst:10094"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.18226" test_ref="oval:org.mitre.oval:tst:21216"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.22360" test_ref="oval:org.mitre.oval:tst:21113"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8553" version="12" class="vulnerability">
      <metadata>
        <title>HTML Element Cross-Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0494" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0494"/>
        <description>Cross-domain vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 allows user-assisted remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted HTML document in a situation where the client user drags one browser window across another browser window, aka "HTML Element Cross-Domain Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-30T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-03-31T14:15:26.751-04:00">DRAFT</status_change>
            <modified comment="Modified the mshtml.dll versions for IE8 on Windows 7 and Windows Server 2008 R2 in order to correctly identify the GDR and LDR branches." date="2010-05-11T13:38:00.735-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="Modified the mshtml.dll versions for IE8 on Windows 7 and Windows Server 2008 R2 in order to correctly identify the GDR and LDR branches." date="2010-05-11T13:41:00.299-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2010-05-31T04:00:51.165-04:00">INTERIM</status_change>
            <status_change date="2010-06-21T04:00:30.388-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6932 - Updated comments to test ID's tst:10804 &amp; tst:10787. And also corrected the version to state ID's ste:6638 &amp; ste:6932 by adding comments according to the MS Bulletins." date="2011-07-18T15:25:00.211-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-07-18T15:26:46.442-04:00">INTERIM</status_change>
            <status_change date="2011-08-08T04:01:06.318-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:04.744-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:04.744-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:04:21.521-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:25:08.559-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:27.730-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8553 - extended definitions of OS are without SP checks" date="2014-07-28T17:36:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:37:55.639-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:37.300-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 6 on Windows 2000 - RTMGDR">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1646" test_ref="oval:org.mitre.oval:tst:21144"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3676" test_ref="oval:org.mitre.oval:tst:20926"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5945" test_ref="oval:org.mitre.oval:tst:21222"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x64, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4672" test_ref="oval:org.mitre.oval:tst:20919"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on XP x86/x64 - GDR">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.17023" test_ref="oval:org.mitre.oval:tst:21218"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on XP x86/x64 - QFE">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21228" test_ref="oval:org.mitre.oval:tst:21283"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Server 2003 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.17023" test_ref="oval:org.mitre.oval:tst:21218"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Server 2003 x86/x64/ia64 - QFE">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21228" test_ref="oval:org.mitre.oval:tst:21283"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.17037" test_ref="oval:org.mitre.oval:tst:20820"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21242" test_ref="oval:org.mitre.oval:tst:21271"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.16000" test_ref="oval:org.mitre.oval:tst:9444"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.18444" test_ref="oval:org.mitre.oval:tst:20823"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.22653" test_ref="oval:org.mitre.oval:tst:21215"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.18000" test_ref="oval:org.mitre.oval:tst:10094"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.18226" test_ref="oval:org.mitre.oval:tst:21216"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.22360" test_ref="oval:org.mitre.oval:tst:21113"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on XP x86/x64, Server 2003 x86/x64 - GDR">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18904" test_ref="oval:org.mitre.oval:tst:21237"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on XP x86/x64, Server 2003 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22995" test_ref="oval:org.mitre.oval:tst:21021"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18904" test_ref="oval:org.mitre.oval:tst:21237"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, all Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22995" test_ref="oval:org.mitre.oval:tst:21021"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - GDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.16000" test_ref="oval:org.mitre.oval:tst:10787"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.16535" test_ref="oval:org.mitre.oval:tst:21250"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - LDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:10804"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.20651" test_ref="oval:org.mitre.oval:tst:21141"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8509" version="3" class="vulnerability">
      <metadata>
        <title>Blended Threat Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2540" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2540"/>
        <description>Apple Safari on Mac OS X, and before 3.1.2 on Windows, does not prompt the user before downloading an object that has an unrecognized content type, which allows remote attackers to place malware into the (1) Desktop directory on Windows or (2) Downloads directory on Mac OS X, and subsequently allows remote attackers to execute arbitrary code on Windows by leveraging an untrusted search path vulnerability in (a) Internet Explorer 7 on Windows XP or (b) the SearchPath function in Windows XP, Vista, and Server 2003 and 2008, aka a "Carpet Bomb" and a "Blended Threat Elevation of Privilege Vulnerability," a different issue than CVE-2008-1032. NOTE: Apple considers this a vulnerability only because the Microsoft products can load application libraries from the desktop and, as of 20080619, has not covered the issue in an advisory for Mac OS X.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-12T23:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-13T17:02:26.536-05:00">DRAFT</status_change>
            <status_change date="2010-02-01T04:00:38.685-05:00">INTERIM</status_change>
            <status_change date="2010-02-22T04:00:11.182-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8509 - extended definitions of OS are without SP checks" date="2014-07-28T17:36:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:37:56.204-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:36.828-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE7/XP x86/x64">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16825" test_ref="oval:org.mitre.oval:tst:9976"/>
        </criteria>
        <criteria operator="AND" comment="IE7/XP x86/x64">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21015" test_ref="oval:org.mitre.oval:tst:9705"/>
        </criteria>
        <criteria operator="AND" comment="Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <criterion comment="The version of Secur32.dll is less than 5.0.2195.7244" test_ref="oval:org.mitre.oval:tst:9587"/>
        </criteria>
        <criteria operator="AND" comment="Windows XP (32-bit)">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="The version of Kernel32.dll is less than 5.1.2600.3541" test_ref="oval:org.mitre.oval:tst:10006"/>
        </criteria>
        <criteria operator="AND" comment="Windows XP (32-bit)">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="The version of Kernel32.dll is less than 5.1.2600.5781" test_ref="oval:org.mitre.oval:tst:9945"/>
        </criteria>
        <criteria operator="AND" comment="XP x64, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x64, Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <criterion comment="The version of Kernel32.dll is less than 5.2.3790.3311" test_ref="oval:org.mitre.oval:tst:9886"/>
        </criteria>
        <criteria operator="AND" comment="XP x64, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x64, Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <criterion comment="The version of Kernel32.dll is less than 5.2.3790.4480" test_ref="oval:org.mitre.oval:tst:10168"/>
        </criteria>
        <criteria operator="AND" comment="Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="the version of Kernel32.dll is greater than or equal 6.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9719"/>
          <criterion comment="The version of Kernel32.dll is less than 6.0.6000.16820" test_ref="oval:org.mitre.oval:tst:10016"/>
        </criteria>
        <criteria operator="AND" comment="Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="the version of Kernel32.dll is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9980"/>
          <criterion comment="The version of Kernel32.dll is less than 6.0.6000.21010" test_ref="oval:org.mitre.oval:tst:9775"/>
        </criteria>
        <criteria operator="AND" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of Kernel32.dll is greater than or equal 6.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9932"/>
          <criterion comment="The version of Kernel32.dll is less than 6.0.6001.18215" test_ref="oval:org.mitre.oval:tst:10000"/>
        </criteria>
        <criteria operator="AND" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of Kernel32.dll is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9167"/>
          <criterion comment="The version of Kernel32.dll is less than 6.0.6001.22376" test_ref="oval:org.mitre.oval:tst:9936"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8506" version="1" class="vulnerability">
      <metadata>
        <title>Uninitialized Memory Corruption Vulnerability (CVE-2010-0247)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0247" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0247"/>
        <description>Microsoft Internet Explorer 5.01 SP4, 6, and 6 SP1 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-21T15:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-01-22T12:33:43.822-05:00">DRAFT</status_change>
            <status_change date="2010-02-08T04:04:18.104-05:00">INTERIM</status_change>
            <status_change date="2010-03-01T04:00:29.351-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="Mshtml.dll version is less than 5.0.3884.1600" test_ref="oval:org.mitre.oval:tst:20918"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1644" test_ref="oval:org.mitre.oval:tst:11530"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3660" test_ref="oval:org.mitre.oval:tst:11697"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5921" test_ref="oval:org.mitre.oval:tst:11468"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4639" test_ref="oval:org.mitre.oval:tst:11646"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8446" version="6" class="vulnerability">
      <metadata>
        <title>Uninitialized Memory Corruption Vulnerability (CVE-2010-0806)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0806" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0806"/>
        <description>Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object, as exploited in the wild in March 2010, aka "Uninitialized Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-30T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-03-31T14:15:27.990-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:26.350-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:12.137-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:25:04.555-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:26.644-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8446 - extended definitions of OS are without SP checks" date="2014-07-28T17:37:00.435-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:39:30.650-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:35.819-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 6 on Windows 2000 - RTMGDR">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1646" test_ref="oval:org.mitre.oval:tst:21144"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3676" test_ref="oval:org.mitre.oval:tst:20926"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5945" test_ref="oval:org.mitre.oval:tst:21222"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x64, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4672" test_ref="oval:org.mitre.oval:tst:20919"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on XP x86/x64 - GDR">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.17023" test_ref="oval:org.mitre.oval:tst:21218"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on XP x86/x64 - QFE">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21228" test_ref="oval:org.mitre.oval:tst:21283"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Server 2003 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.17023" test_ref="oval:org.mitre.oval:tst:21218"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Server 2003 x86/x64/ia64 - QFE">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21228" test_ref="oval:org.mitre.oval:tst:21283"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.17037" test_ref="oval:org.mitre.oval:tst:20820"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21242" test_ref="oval:org.mitre.oval:tst:21271"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.16000" test_ref="oval:org.mitre.oval:tst:9444"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.18444" test_ref="oval:org.mitre.oval:tst:20823"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.22653" test_ref="oval:org.mitre.oval:tst:21215"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.18000" test_ref="oval:org.mitre.oval:tst:10094"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.18226" test_ref="oval:org.mitre.oval:tst:21216"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.22360" test_ref="oval:org.mitre.oval:tst:21113"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8438" version="3" class="vulnerability">
      <metadata>
        <title>SMB Pathname Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0020" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0020"/>
        <description>The SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate request fields, which allows remote authenticated users to execute arbitrary code via a malformed request, aka "SMB Pathname Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-02-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-02-10T13:39:54.857-05:00">DRAFT</status_change>
            <status_change date="2010-03-01T04:00:25.104-05:00">INTERIM</status_change>
            <status_change date="2010-03-22T04:00:14.869-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:01.915-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:01.915-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:04:17.287-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4 or later">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Srv.sys version is less than 5.0.2195.7365" test_ref="oval:org.mitre.oval:tst:21057"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="Srv.sys version is less than 5.1.2600.3662" test_ref="oval:org.mitre.oval:tst:20948"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Srv.sys version is less than 5.1.2600.5923" test_ref="oval:org.mitre.oval:tst:21069"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="Srv.sys version is less than 5.2.3790.4634" test_ref="oval:org.mitre.oval:tst:21015"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9543"/>
          <criterion comment="Srv.sys version is less than 6.0.6000.16977" test_ref="oval:org.mitre.oval:tst:20632"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:8674"/>
          <criterion comment="Srv.sys version is less than 6.0.6000.21179" test_ref="oval:org.mitre.oval:tst:21047"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9601"/>
          <criterion comment="Srv.sys version is less than 6.0.6001.18381" test_ref="oval:org.mitre.oval:tst:20390"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9666"/>
          <criterion comment="Srv.sys version is less than 6.0.6001.22581" test_ref="oval:org.mitre.oval:tst:21064"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6002.18000" test_ref="oval:org.mitre.oval:tst:20868"/>
          <criterion comment="Srv.sys version is less than 6.0.6002.18164" test_ref="oval:org.mitre.oval:tst:20904"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:21089"/>
          <criterion comment="Srv.sys version is less than 6.0.6002.22286" test_ref="oval:org.mitre.oval:tst:20763"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.1.7600.16000" test_ref="oval:org.mitre.oval:tst:20615"/>
          <criterion comment="Srv.sys version is less than 6.1.7600.16481" test_ref="oval:org.mitre.oval:tst:21084"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:20704"/>
          <criterion comment="Srv.sys version is less than 6.1.7600.20591" test_ref="oval:org.mitre.oval:tst:21034"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8429" version="1" class="vulnerability">
      <metadata>
        <title>MS Paint Integer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0028" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0028"/>
        <description>Integer overflow in Microsoft Paint in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted JPEG (.JPG) file, aka "MS Paint Integer Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-02-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-02-10T13:38:46.281-05:00">DRAFT</status_change>
            <status_change date="2010-03-01T04:00:24.704-05:00">INTERIM</status_change>
            <status_change date="2010-03-22T04:00:14.300-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4 or later">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Mspaint.exe is less than 5.0.2195.7368" test_ref="oval:org.mitre.oval:tst:20476"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="the version of Mspaint.exe is less than 5.1.2600.3660" test_ref="oval:org.mitre.oval:tst:21072"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of Mspaint.exe is less than 5.1.2600.5918" test_ref="oval:org.mitre.oval:tst:20485"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of Mspaint.exe is less than 5.2.3790.4638" test_ref="oval:org.mitre.oval:tst:21071"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8428" version="1" class="vulnerability">
      <metadata>
        <title>Kerberos Null Pointer Dereference Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0035" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0035"/>
        <description>The Key Distribution Center (KDC) in Kerberos in Microsoft Windows 2000 SP4, Server 2003 SP2, and Server 2008 Gold and SP2, when a trust relationship with a non-Windows Kerberos realm exists, allows remote authenticated users to cause a denial of service (NULL pointer dereference and domain controller outage) via a crafted Ticket Granting Ticket (TGT) renewal request, aka "Kerberos Null Pointer Dereference Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-02-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-02-10T13:40:19.771-05:00">DRAFT</status_change>
            <status_change date="2010-03-01T04:00:24.231-05:00">INTERIM</status_change>
            <modified comment="Update for CVE-2010-0035 for bulletin MS10-014" date="2010-03-08T14:55:00.741-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2010-05-17T04:01:25.410-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4 or later">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criteria operator="OR" comment="Windows NT server product option">
            <criterion comment="this is an NT Server (stand-alone)" test_ref="oval:org.mitre.oval:tst:2408"/>
            <criterion comment="this is an NT Server (domain controller)" test_ref="oval:org.mitre.oval:tst:3035"/>
          </criteria>
          <criterion comment="the system is being used as AD - DomainRole is 4 or 5" test_ref="oval:org.mitre.oval:tst:10696"/>
          <criterion comment="the version of Kdcsvc.dll is less than 5.0.2195.7361" test_ref="oval:org.mitre.oval:tst:20657"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the system is being used as AD - DomainRole is 4 or 5" test_ref="oval:org.mitre.oval:tst:10696"/>
          <criterion comment="the version of Kdcsvc.dll is less than 5.2.3790.4628" test_ref="oval:org.mitre.oval:tst:20941"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Server 2008 32bit/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the system is being used as AD - DomainRole is 4 or 5" test_ref="oval:org.mitre.oval:tst:10696"/>
          <criterion comment="the version of Kdcsvc.dll is less than 6.0.6001.18374" test_ref="oval:org.mitre.oval:tst:21000"/>
          <criterion comment="the version of Kdcsvc.dll is greater than or equal 6.0.6001.18000" test_ref="oval:org.mitre.oval:tst:20922"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Server 2008 32bit/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the system is being used as AD - DomainRole is 4 or 5" test_ref="oval:org.mitre.oval:tst:10696"/>
          <criterion comment="the version of Kdcsvc.dll is less than 6.0.6001.22574" test_ref="oval:org.mitre.oval:tst:21088"/>
          <criterion comment="the version of Kdcsvc.dll is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:20781"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Server 2008 SP2 32bit/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="the system is being used as AD - DomainRole is 4 or 5" test_ref="oval:org.mitre.oval:tst:10696"/>
          <criterion comment="the version of Kdcsvc.dll is less than 6.0.6002.18157" test_ref="oval:org.mitre.oval:tst:20849"/>
          <criterion comment="the version of Kdcsvc.dll is greater than or equal 6.0.6002.18000" test_ref="oval:org.mitre.oval:tst:20843"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Server 2008 SP2 32bit/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="the system is being used as AD - DomainRole is 4 or 5" test_ref="oval:org.mitre.oval:tst:10696"/>
          <criterion comment="the version of Kdcsvc.dll is less than 6.0.6002.22280" test_ref="oval:org.mitre.oval:tst:20839"/>
          <criterion comment="the version of Kdcsvc.dll is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:20769"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8424" version="7" class="vulnerability">
      <metadata>
        <title>Microsoft Data Analyzer ActiveX Control Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0252" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0252"/>
        <description>The Microsoft Data Analyzer ActiveX control (aka the Office Excel ActiveX control for Data Analysis) in max3activex.dll in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote attackers to execute arbitrary code via a crafted web page that corrupts the "system state," aka "Microsoft Data Analyzer ActiveX Control Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-02-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-02-10T13:39:10.997-05:00">DRAFT</status_change>
            <status_change date="2010-03-01T04:00:23.593-05:00">INTERIM</status_change>
            <status_change date="2010-03-22T04:00:13.627-04:00">ACCEPTED</status_change>
            <modified comment="Added additional criteria for Active X control detection." date="2010-06-14T10:40:00.826-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2010-06-14T10:46:39.917-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:50:06.002-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:03.603-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:03.603-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:04:16.525-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:3992 - modified vulnerabilities ofÂ MS Visual C++ Â  (winsxs folder checks were modified)" date="2014-04-17T13:09:00.881-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-04-17T13:11:53.249-04:00">INTERIM</status_change>
            <status_change date="2014-05-05T04:00:33.271-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
          <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
          <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
        </criteria>
        <criteria operator="OR">
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{E0ECA9C3-D669-4EF4-8231-00724ED9288F}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:20990"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{E0ECA9C3-D669-4EF4-8231-00724ED9288F}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:21016"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{14FD1463-1F3F-4357-9C03-2080B442F503}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:27468"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{14FD1463-1F3F-4357-9C03-2080B442F503}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:27497"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{E9CB13DB-20AB-43C5-B283-977C58FB5754}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:27250"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{E9CB13DB-20AB-43C5-B283-977C58FB5754}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:27426"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8421" version="2" class="vulnerability">
      <metadata>
        <title>HTML Object Memory Corruption Vulnerability (CVE-2010-0491)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer 5.01</product>
          <product>Microsoft Internet Explorer 6</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0491" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0491"/>
        <description>Use-after-free vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, and 6 SP1 allows remote attackers to execute arbitrary code by changing unspecified properties of an HTML object that has an onreadystatechange event handler, aka "HTML Object Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-30T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-03-31T14:15:25.732-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:24.442-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:10.622-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 5.01 Service Pack 4 on Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="Mshtml.dll version is less than 5.0.3886.1900" test_ref="oval:org.mitre.oval:tst:20983"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on Windows 2000 - RTMGDR">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1646" test_ref="oval:org.mitre.oval:tst:21144"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x86 SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3676" test_ref="oval:org.mitre.oval:tst:20926"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x86 SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5945" test_ref="oval:org.mitre.oval:tst:21222"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x64 SP2, Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4672" test_ref="oval:org.mitre.oval:tst:20919"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:842" version="1" class="vulnerability">
      <metadata>
        <title>MS Windows Media Service Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows Media Services</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0905" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0905"/>
        <description>Unknown vulnerability in Windows Media Station Service and Windows Media Monitor Service components of Windows Media Services 4.1 allows remote attackers to cause a denial of service (disallowing new connections) via a certain sequence of TCP/IP packets.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-09T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2006-10-31T04:13:00.000-04:00" comment="Replaced reference to obj:1374 with reference to obj:1550 since it referencess Product\Options and not ProductOptions in the controlset registry key.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <modified comment="Fixed obj:1078: Removed HKEY_LOCAL_MACHINE\ from the key, as it's specified as the hive.  Implemented by Harvey Rubinovitz." date="2007-01-22T00:34:00.741-05:00">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.292-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.906-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Software section">
          <criteria operator="AND" comment="Windows Media Services 4.1 is installed on Microsoft Windows 2000 Server">
            <criterion comment="Windows Media Services 4.1 is installed" test_ref="oval:org.mitre.oval:tst:1602"/>
            <criteria operator="AND" comment="Windows 2000 Server is installed">
              <criterion comment="Windows 2000 is installed" test_ref="oval:org.mitre.oval:tst:3085"/>
              <criteria operator="OR" comment="Windows NT server product option">
                <criterion comment="this is an NT Server (stand-alone)" test_ref="oval:org.mitre.oval:tst:2408"/>
                <criterion comment="this is an NT Server (domain controller)" test_ref="oval:org.mitre.oval:tst:3035"/>
              </criteria>
            </criteria>
          </criteria>
          <criterion comment="the version of nscm.exe is less than 4.1.0.3934" test_ref="oval:org.mitre.oval:tst:1601"/>
          <criterion comment="the version of nspmon.exe is less than 4.1.0.3934" test_ref="oval:org.mitre.oval:tst:1600"/>
          <criterion negate="true" comment="the patch kb832359 is installed" test_ref="oval:org.mitre.oval:tst:1599"/>
        </criteria>
        <criteria operator="AND" comment="Configuration section">
          <criterion negate="true" comment="configured to only offer streaming media over unicast" test_ref="oval:org.mitre.oval:tst:1598"/>
          <criterion negate="true" comment="the Windows Media Station service is disabled" test_ref="oval:org.mitre.oval:tst:1597"/>
          <criterion negate="true" comment="the Windows Media Monitor service is disabled" test_ref="oval:org.mitre.oval:tst:1596"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:841" version="3" class="vulnerability">
      <metadata>
        <title>Unhandled Exception Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference ref_id="CVE-2006-3648" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3648" source="CVE"/>
        <description>Unspecified vulnerability in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 and 2003 SP1, allows remote attackers to execute arbitrary code via unspecified vectors involving unhandled exceptions, memory resident applications, and incorrectly "unloading chained exception."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:39.810-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:49.708-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:841 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:04:44.298-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:48.393-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win2K,SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="The version of Kernel32.dll is less than 5.0.2195.7099." test_ref="oval:org.mitre.oval:tst:80"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP1">
          <extend_definition comment="Microsoft Windows XP SP1 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          <criterion comment="The version of Kernel32.dll is less than 5.1.2600.1869." test_ref="oval:org.mitre.oval:tst:31"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="The version of Kernel32.dll is less than 5.1.2600.2945." test_ref="oval:org.mitre.oval:tst:45"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP1 (64-bit)">
          <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="The version of Kernel32.dll is less than 5.2.3790.2741." test_ref="oval:org.mitre.oval:tst:104"/>
        </criteria>
        <criteria operator="AND" comment="S03-Gold">
          <extend_definition comment="Microsoft Windows Server 2003 (x86) Gold is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="The version of Kernel32.dll is less than 5.2.3790.556." test_ref="oval:org.mitre.oval:tst:63"/>
        </criteria>
        <criteria operator="AND" comment="S03,SP1">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="The version of Kernel32.dll is less than 5.2.3790.2741." test_ref="oval:org.mitre.oval:tst:104"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8399" version="1" class="vulnerability">
      <metadata>
        <title>MSO.DLL Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Office XP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0243" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0243"/>
        <description>Buffer overflow in MSO.DLL in Microsoft Office XP SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Office document, aka "MSO.DLL Buffer Overflow."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-02-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-02-10T13:38:36.382-05:00">DRAFT</status_change>
            <status_change date="2010-03-01T04:00:22.458-05:00">INTERIM</status_change>
            <status_change date="2010-03-22T04:00:12.421-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Office XP is installed" definition_ref="oval:org.mitre.oval:def:663"/>
        <criterion comment="Mso.dll version is less than 10.0.6858.0" test_ref="oval:org.mitre.oval:tst:20723"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8392" version="1" class="vulnerability">
      <metadata>
        <title>Windows Kernel Double Free Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0233" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0233"/>
        <description>Double free vulnerability in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows local users to gain privileges via a crafted application, aka "Windows Kernel Double Free Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-02-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-02-10T13:40:36.420-05:00">DRAFT</status_change>
            <status_change date="2010-03-01T04:00:21.474-05:00">INTERIM</status_change>
            <status_change date="2010-03-22T04:00:11.557-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4 or later">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 5.0.2195.7364" test_ref="oval:org.mitre.oval:tst:20965"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 5.1.2600.3654" test_ref="oval:org.mitre.oval:tst:20861"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 5.1.2600.5913" test_ref="oval:org.mitre.oval:tst:20875"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is less than 5.2.3790.4637" test_ref="oval:org.mitre.oval:tst:21038"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6000.16000" test_ref="oval:org.mitre.oval:tst:10882"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6000.16973" test_ref="oval:org.mitre.oval:tst:21001"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:10762"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6000.21175" test_ref="oval:org.mitre.oval:tst:21086"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6001.18000" test_ref="oval:org.mitre.oval:tst:10821"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6001.18377" test_ref="oval:org.mitre.oval:tst:21094"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:10407"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6001.22577" test_ref="oval:org.mitre.oval:tst:20290"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6002.18000" test_ref="oval:org.mitre.oval:tst:10870"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6002.18160" test_ref="oval:org.mitre.oval:tst:20720"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10581"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6002.22283" test_ref="oval:org.mitre.oval:tst:20937"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86 - GDR">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.1.7600.16000" test_ref="oval:org.mitre.oval:tst:21030"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.1.7600.16481" test_ref="oval:org.mitre.oval:tst:20790"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86 - LDR">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:20969"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.1.7600.20591" test_ref="oval:org.mitre.oval:tst:20976"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8344" version="1" class="vulnerability">
      <metadata>
        <title>Windows Kernel Exception Handler Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0232" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0232"/>
        <description>The kernel in Microsoft Windows NT 3.1 through Windows 7, including Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, and Windows Server 2008 Gold and SP2, when access to 16-bit applications is enabled on a 32-bit x86 platform, does not properly validate certain BIOS calls, which allows local users to gain privileges by crafting a VDM_TIB data structure in the Thread Environment Block (TEB), and then calling the NtVdmControl function to start the Windows Virtual DOS Machine (aka NTVDM) subsystem, leading to improperly handled exceptions involving the #GP trap handler (nt!KiTrap0D), aka "Windows Kernel Exception Handler Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-02-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-02-10T13:40:37.616-05:00">DRAFT</status_change>
            <status_change date="2010-03-01T04:00:19.970-05:00">INTERIM</status_change>
            <status_change date="2010-03-22T04:00:10.417-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4 or later">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 5.0.2195.7364" test_ref="oval:org.mitre.oval:tst:20965"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 5.1.2600.3654" test_ref="oval:org.mitre.oval:tst:20861"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 5.1.2600.5913" test_ref="oval:org.mitre.oval:tst:20875"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Server 2003 x86 SP2">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 5.2.3790.4637" test_ref="oval:org.mitre.oval:tst:21038"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86 - GDR">
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6000.16000" test_ref="oval:org.mitre.oval:tst:10882"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6000.16973" test_ref="oval:org.mitre.oval:tst:21001"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86 - LDR">
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:10762"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6000.21175" test_ref="oval:org.mitre.oval:tst:21086"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86, Server 2008 32bit - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6001.18000" test_ref="oval:org.mitre.oval:tst:10821"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6001.18377" test_ref="oval:org.mitre.oval:tst:21094"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86, Server 2008 32bit - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:10407"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6001.22577" test_ref="oval:org.mitre.oval:tst:20290"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86, Server 2008 SP2 32bit - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6002.18000" test_ref="oval:org.mitre.oval:tst:10870"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6002.18160" test_ref="oval:org.mitre.oval:tst:20720"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86, Server 2008 SP2 32bit - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10581"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6002.22283" test_ref="oval:org.mitre.oval:tst:20937"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86 - GDR">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.1.7600.16000" test_ref="oval:org.mitre.oval:tst:21030"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.1.7600.16481" test_ref="oval:org.mitre.oval:tst:20790"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86 - LDR">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:20969"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.1.7600.20591" test_ref="oval:org.mitre.oval:tst:20976"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8324" version="5" class="vulnerability">
      <metadata>
        <title>Microtype Express Compressed Fonts Integer Flaw in the LZCOMP Decompressor Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0018" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0018"/>
        <description>Integer overflow in the Embedded OpenType (EOT) Font Engine (t2embed.dll) in Microsoft Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP2; Windows Server 2008 Gold, SP2, and R2; and Windows 7 allows remote attackers to execute arbitrary code via compressed data that represents a crafted EOT font, aka "Microtype Express Compressed Fonts Integer Flaw in the LZCOMP Decompressor Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-12T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-01-13T17:02:56.446-05:00">DRAFT</status_change>
            <status_change date="2010-02-01T04:00:36.628-05:00">INTERIM</status_change>
            <status_change date="2010-02-22T04:00:09.040-05:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:58.415-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:58.415-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:04:13.825-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4217 - modified states" date="2014-02-28T15:16:00.713-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-28T15:17:21.123-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:34.906-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4 or later">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criteria operator="OR" comment="Fontsub.dll &lt; 5.0.2195.7348 or T2embed.dll &lt; 5.0.2195.7348">
            <criterion comment="the version of Fontsub.dll is less than 5.0.2195.7348" test_ref="oval:org.mitre.oval:tst:20934"/>
            <criterion comment="the version of T2embed.dll is less than 5.0.2195.7348" test_ref="oval:org.mitre.oval:tst:20771"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criteria operator="OR" comment="Fontsub.dll &lt; 5.1.2600.3634 or T2embed.dll &lt; 5.1.2600.3634">
            <criterion comment="the version of Fontsub.dll is less than 5.1.2600.3634" test_ref="oval:org.mitre.oval:tst:20493"/>
            <criterion comment="the version of T2embed.dll is less than 5.1.2600.3634" test_ref="oval:org.mitre.oval:tst:20574"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criteria operator="OR" comment="Fontsub.dll &lt; 5.1.2600.5888 or T2embed.dll &lt; 5.1.2600.5888">
            <criterion comment="the version of Fontsub.dll is less than 5.1.2600.5888" test_ref="oval:org.mitre.oval:tst:20330"/>
            <criterion comment="the version of T2embed.dll is less than 5.1.2600.5888" test_ref="oval:org.mitre.oval:tst:20465"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criteria operator="OR" comment="Fontsub.dll &lt; 5.2.3790.4603 or T2embed.dll &lt; 5.2.3790.4603">
            <criterion comment="the version of Fontsub.dll is less than 5.2.3790.4603" test_ref="oval:org.mitre.oval:tst:20803"/>
            <criterion comment="the version of T2embed.dll is less than 5.2.3790.4603" test_ref="oval:org.mitre.oval:tst:20441"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="Fontsub.dll &lt; 6.0.6000.16939 or T2embed.dll &lt;6.0.6000.16939">
            <criterion comment="the version of Fontsub.dll is less than 6.0.6000.16939" test_ref="oval:org.mitre.oval:tst:20960"/>
            <criterion comment="the version of T2embed.dll is less than 6.0.6000.16939" test_ref="oval:org.mitre.oval:tst:20880"/>
          </criteria>
          <criteria operator="OR" comment="Fontsub.dll >= 6.0.6000.16000 or T2embed.dll >= 6.0.6000.16000">
            <criterion comment="the version of Fontsub.dll is greater than or equal 6.0.6000.16000" test_ref="oval:org.mitre.oval:tst:10227"/>
            <criterion comment="the version of T2embed.dll is greater than or equal 6.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9969"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="Fontsub.dll &lt; 6.0.6000.21142 or T2embed.dll &lt;6.0.6000.21142">
            <criterion comment="the version of Fontsub.dll is less than 6.0.6000.21142" test_ref="oval:org.mitre.oval:tst:20834"/>
            <criterion comment="the version of T2embed.dll is less than 6.0.6000.21142" test_ref="oval:org.mitre.oval:tst:20901"/>
          </criteria>
          <criteria operator="OR" comment="Fontsub.dll >= 6.0.6000.20000 or T2embed.dll >= 6.0.6000.20000">
            <criterion comment="the version of Fontsub.dll is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:10116"/>
            <criterion comment="the version of T2embed.dll is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:10120"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Fontsub.dll &lt; 6.0.6001.18344 or T2embed.dll &lt;6.0.6001.18344">
            <criterion comment="the version of Fontsub.dll is less than 6.0.6001.18344" test_ref="oval:org.mitre.oval:tst:20514"/>
            <criterion comment="the version of T2embed.dll is less than 6.0.6001.18344" test_ref="oval:org.mitre.oval:tst:20947"/>
          </criteria>
          <criteria operator="OR" comment="Fontsub.dll >= 6.0.6001.18000 or T2embed.dll >= 6.0.6001.18000">
            <criterion comment="the version of Fontsub.dll is greater than or equal 6.0.6001.18000" test_ref="oval:org.mitre.oval:tst:10215"/>
            <criterion comment="the version of T2embed.dll is greater than or equal 6.0.6001.18000" test_ref="oval:org.mitre.oval:tst:10202"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Fontsub.dll &lt; 6.0.6001.22544 or T2embed.dll &lt;6.0.6001.22544">
            <criterion comment="the version of Fontsub.dll is less than 6.0.6001.22544" test_ref="oval:org.mitre.oval:tst:20693"/>
            <criterion comment="the version of T2embed.dll is less than 6.0.6001.22544" test_ref="oval:org.mitre.oval:tst:20548"/>
          </criteria>
          <criteria operator="OR" comment="Fontsub.dll >= 6.0.6001.22000 or T2embed.dll >= 6.0.6001.22000">
            <criterion comment="the version of Fontsub.dll is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9819"/>
            <criterion comment="the version of T2embed.dll is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:10118"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="Fontsub.dll &lt; 6.0.6002.18124 or T2embed.dll &lt;6.0.6002.18124">
            <criterion comment="the version of Fontsub.dll is less than 6.0.6002.18124" test_ref="oval:org.mitre.oval:tst:20931"/>
            <criterion comment="the version of T2embed.dll is less than 6.0.6002.18124" test_ref="oval:org.mitre.oval:tst:20968"/>
          </criteria>
          <criteria operator="OR" comment="Fontsub.dll >= 6.0.6002.18000 or T2embed.dll >= 6.0.6002.18000">
            <criterion comment="the version of Fontsub.dll is greater than or equal 6.0.6002.18000" test_ref="oval:org.mitre.oval:tst:20873"/>
            <criterion comment="the version of T2embed.dll is greater than or equal 6.0.6002.18000" test_ref="oval:org.mitre.oval:tst:20791"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="Fontsub.dll &lt; 6.0.6002.22247 or T2embed.dll &lt;6.0.6002.22247">
            <criterion comment="the version of Fontsub.dll is less than 6.0.6002.22247" test_ref="oval:org.mitre.oval:tst:20307"/>
            <criterion comment="the version of T2embed.dll is less than 6.0.6002.22247" test_ref="oval:org.mitre.oval:tst:20076"/>
          </criteria>
          <criteria operator="OR" comment="Fontsub.dll >= 6.0.6002.22000 or T2embed.dll >= 6.0.6002.22000">
            <criterion comment="the version of Fontsub.dll is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10029"/>
            <criterion comment="the version of T2embed.dll is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10002"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR">
            <criterion comment="the version of Fontsub.dll is less than 6.1.7600.16444" test_ref="oval:org.mitre.oval:tst:20573"/>
            <criterion comment="the version of T2embed.dll is less than 6.1.7600.16444" test_ref="oval:org.mitre.oval:tst:20972"/>
          </criteria>
          <criteria operator="OR">
            <criterion comment="the version of Fontsub.dll is greater than or equal 6.1.7600.16000" test_ref="oval:org.mitre.oval:tst:20730"/>
            <criterion comment="the version of T2embed.dll is greater than or equal 6.1.7600.16000" test_ref="oval:org.mitre.oval:tst:20874"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR">
            <criterion comment="the version of Fontsub.dll is less than 6.1.7600.20553" test_ref="oval:org.mitre.oval:tst:20953"/>
            <criterion comment="the version of T2embed.dll is less than 6.1.7600.20553" test_ref="oval:org.mitre.oval:tst:20599"/>
          </criteria>
          <criteria operator="OR">
            <criterion comment="the version of Fontsub.dll is greater than or equal 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:20857"/>
            <criterion comment="the version of T2embed.dll is greater than or equal 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:20099"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8314" version="3" class="vulnerability">
      <metadata>
        <title>SMB Null Pointer Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0022" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0022"/>
        <description>The SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate the share and servername fields in SMB packets, which allows remote attackers to cause a denial of service (system hang) via a crafted packet, aka "SMB Null Pointer Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-02-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-02-10T13:39:55.645-05:00">DRAFT</status_change>
            <status_change date="2010-03-01T04:00:19.120-05:00">INTERIM</status_change>
            <status_change date="2010-03-22T04:00:09.453-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:00.181-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:00.181-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:04:12.938-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4 or later">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Srv.sys version is less than 5.0.2195.7365" test_ref="oval:org.mitre.oval:tst:21057"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="Srv.sys version is less than 5.1.2600.3662" test_ref="oval:org.mitre.oval:tst:20948"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Srv.sys version is less than 5.1.2600.5923" test_ref="oval:org.mitre.oval:tst:21069"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="Srv.sys version is less than 5.2.3790.4634" test_ref="oval:org.mitre.oval:tst:21015"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9543"/>
          <criterion comment="Srv.sys version is less than 6.0.6000.16977" test_ref="oval:org.mitre.oval:tst:20632"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:8674"/>
          <criterion comment="Srv.sys version is less than 6.0.6000.21179" test_ref="oval:org.mitre.oval:tst:21047"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9601"/>
          <criterion comment="Srv.sys version is less than 6.0.6001.18381" test_ref="oval:org.mitre.oval:tst:20390"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9666"/>
          <criterion comment="Srv.sys version is less than 6.0.6001.22581" test_ref="oval:org.mitre.oval:tst:21064"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6002.18000" test_ref="oval:org.mitre.oval:tst:20868"/>
          <criterion comment="Srv.sys version is less than 6.0.6002.18164" test_ref="oval:org.mitre.oval:tst:20904"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:21089"/>
          <criterion comment="Srv.sys version is less than 6.0.6002.22286" test_ref="oval:org.mitre.oval:tst:20763"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.1.7600.16000" test_ref="oval:org.mitre.oval:tst:20615"/>
          <criterion comment="Srv.sys version is less than 6.1.7600.16481" test_ref="oval:org.mitre.oval:tst:21084"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:20704"/>
          <criterion comment="Srv.sys version is less than 6.1.7600.20591" test_ref="oval:org.mitre.oval:tst:21034"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8304" version="1" class="vulnerability">
      <metadata>
        <title>CSRSS Local Privilege Elevation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0023" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0023"/>
        <description>The Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly kill processes after a logout, which allows local users to obtain sensitive information or gain privileges via a crafted application that continues to execute throughout the logout of one user and the login session of the next user, aka "CSRSS Local Privilege Elevation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-02-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-02-10T13:39:36.149-05:00">DRAFT</status_change>
            <status_change date="2010-03-01T04:00:18.419-05:00">INTERIM</status_change>
            <status_change date="2010-03-22T04:00:08.964-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4 or later">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Csrsrv.dll version is less than 5.0.2195.7366" test_ref="oval:org.mitre.oval:tst:20352"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="Csrsrv.dll version is less than 5.1.2600.3657" test_ref="oval:org.mitre.oval:tst:20878"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Csrsrv.dll version is less than 5.1.2600.5915" test_ref="oval:org.mitre.oval:tst:21011"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="Csrsrv.dll version is less than 5.2.3790.4635" test_ref="oval:org.mitre.oval:tst:21035"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8302" version="12" class="vulnerability">
      <metadata>
        <title>Uninitialized Memory Corruption Vulnerability (CVE-2010-0490)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0490" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0490"/>
        <description>Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-30T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-03-31T14:15:24.602-04:00">DRAFT</status_change>
            <modified comment="Modified the mshtml.dll versions for IE8 on Windows 7 and Windows Server 2008 R2 in order to correctly identify the GDR and LDR branches." date="2010-05-11T13:38:00.735-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="Modified the mshtml.dll versions for IE8 on Windows 7 and Windows Server 2008 R2 in order to correctly identify the GDR and LDR branches." date="2010-05-11T13:41:00.299-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2010-05-31T04:00:46.225-04:00">INTERIM</status_change>
            <status_change date="2010-06-21T04:00:28.200-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6932 - Updated comments to test ID's tst:10804 &amp; tst:10787. And also corrected the version to state ID's ste:6638 &amp; ste:6932 by adding comments according to the MS Bulletins." date="2011-07-18T15:25:00.211-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-07-18T15:26:50.754-04:00">INTERIM</status_change>
            <status_change date="2011-08-08T04:01:02.260-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:06.837-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:06.837-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:04:11.837-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:25:05.018-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:26.293-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8302 - extended definitions of OS are without SP checks" date="2014-07-28T17:37:00.435-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:39:33.278-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:34.563-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 6 on Windows 2000 - RTMGDR">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1646" test_ref="oval:org.mitre.oval:tst:21144"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3676" test_ref="oval:org.mitre.oval:tst:20926"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5945" test_ref="oval:org.mitre.oval:tst:21222"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x64, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4672" test_ref="oval:org.mitre.oval:tst:20919"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on XP x86/x64 - GDR">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.17023" test_ref="oval:org.mitre.oval:tst:21218"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on XP x86/x64 - QFE">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21228" test_ref="oval:org.mitre.oval:tst:21283"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Server 2003 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.17023" test_ref="oval:org.mitre.oval:tst:21218"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Server 2003 x86/x64/ia64 - QFE">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21228" test_ref="oval:org.mitre.oval:tst:21283"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.17037" test_ref="oval:org.mitre.oval:tst:20820"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21242" test_ref="oval:org.mitre.oval:tst:21271"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.16000" test_ref="oval:org.mitre.oval:tst:9444"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.18444" test_ref="oval:org.mitre.oval:tst:20823"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.22653" test_ref="oval:org.mitre.oval:tst:21215"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.18000" test_ref="oval:org.mitre.oval:tst:10094"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.18226" test_ref="oval:org.mitre.oval:tst:21216"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.22360" test_ref="oval:org.mitre.oval:tst:21113"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on XP x86/x64, Server 2003 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18904" test_ref="oval:org.mitre.oval:tst:21237"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on XP x86/x64, Server 2003 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22995" test_ref="oval:org.mitre.oval:tst:21021"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, all Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18904" test_ref="oval:org.mitre.oval:tst:21237"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22995" test_ref="oval:org.mitre.oval:tst:21021"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - GDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.16000" test_ref="oval:org.mitre.oval:tst:10787"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.16535" test_ref="oval:org.mitre.oval:tst:21250"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - LDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:10804"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.20651" test_ref="oval:org.mitre.oval:tst:21141"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:83" version="4" class="vulnerability">
      <metadata>
        <title>Microsoft SQL Server 3-Function Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft SQL Server</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0542" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0542"/>
        <description>Buffer overflows in Microsoft SQL Server 7.0 and 2000 allow attackers with access to SQL Server to execute arbitrary code through the functions (1) raiserror, (2) formatmessage, or (3) xp_sprintf.  NOTE: the C runtime format string vulnerability reported in MS01-060 is identified by CVE-2001-0879.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
            </submitted>
            <modified date="2005-04-08T12:00:00.000-04:00" comment="modified wft-227 - corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-11T08:48:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T10:57:00.000-04:00" comment="modified wft-227 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:83 - Corrected typo in product name" date="2011-04-27T10:10:00.373-04:00">
              <contributor organization="The MITRE Corporation">Mike Lah</contributor>
            </modified>
            <status_change date="2011-04-27T10:11:15.271-04:00">INTERIM</status_change>
            <status_change date="2011-05-16T04:03:32.410-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="SQL Server 2000 is installed" test_ref="oval:org.mitre.oval:tst:2977"/>
        <criterion comment="File sqlservr.exe version3 less than 2000.80.428.0" test_ref="oval:org.mitre.oval:tst:2965"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8278" version="1" class="vulnerability">
      <metadata>
        <title>SMB Client Pool Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0016" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0016"/>
        <description>The SMB client implementation in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly validate response fields, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code via a crafted response, aka "SMB Client Pool Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-02-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-02-10T13:38:51.855-05:00">DRAFT</status_change>
            <status_change date="2010-03-01T04:00:16.703-05:00">INTERIM</status_change>
            <status_change date="2010-03-22T04:00:07.474-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4 or later">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Mrxsmb.sys version is less than 5.0.2195.7362" test_ref="oval:org.mitre.oval:tst:20774"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="Mrxsmb.sys version is less than 5.1.2600.3652" test_ref="oval:org.mitre.oval:tst:21042"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Mrxsmb.sys version is less than 5.1.2600.5911" test_ref="oval:org.mitre.oval:tst:20490"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="Mrxsmb.sys version is less than 5.2.3790.4630" test_ref="oval:org.mitre.oval:tst:20830"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8267" version="12" class="vulnerability">
      <metadata>
        <title>Uninitialized Memory Corruption Vulnerability (CVE-2010-0248)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0248" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0248"/>
        <description>Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "HTML Object Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-21T15:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-01-22T12:33:42.498-05:00">DRAFT</status_change>
            <modified comment="Updated to include tests for Windows XP SP2 (x86) running IE 7.  Microsoft bulletin MS10-002 (associated File Information article) did not include a reference to Windows XP SP2 (x86) running IE 7.0, though this is a vulnerable configuration and updated by the patch referenced in the article." date="2010-01-27T13:28:00.020-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2010-02-15T04:00:07.637-05:00">INTERIM</status_change>
            <status_change date="2010-03-08T04:00:13.167-05:00">ACCEPTED</status_change>
            <modified comment="Modified the mshtml.dll versions for IE8 on Windows 7 and Windows Server 2008 R2 in order to correctly identify the GDR and LDR branches." date="2010-05-11T13:38:00.735-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2010-05-11T13:41:03.246-04:00">INTERIM</status_change>
            <modified comment="Modified the mshtml.dll versions for IE8 on Windows 7 and Windows Server 2008 R2 in order to correctly identify the GDR and LDR branches." date="2010-05-11T13:41:00.299-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2010-05-31T04:00:44.955-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6932 - Updated comments to test ID's tst:10804 &amp; tst:10787. And also corrected the version to state ID's ste:6638 &amp; ste:6932 by adding comments according to the MS Bulletins." date="2011-07-18T15:25:00.211-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-07-18T15:26:51.808-04:00">INTERIM</status_change>
            <status_change date="2011-08-08T04:01:01.011-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:55.634-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:55.634-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:04:09.941-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:25:04.076-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:25.552-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8267 - extended definitions of OS are without SP checks" date="2014-07-28T17:37:00.435-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:39:29.620-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:33.705-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE6/Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1644" test_ref="oval:org.mitre.oval:tst:11530"/>
        </criteria>
        <criteria operator="AND" comment="IE6/XP">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3660" test_ref="oval:org.mitre.oval:tst:11697"/>
        </criteria>
        <criteria operator="AND" comment="IE6/XP">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5921" test_ref="oval:org.mitre.oval:tst:11468"/>
        </criteria>
        <criteria operator="AND" comment="IE6/XP x64/server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4639" test_ref="oval:org.mitre.oval:tst:11646"/>
        </criteria>
        <criteria operator="AND" comment="IE7/XP x86/x64">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16981" test_ref="oval:org.mitre.oval:tst:11559"/>
        </criteria>
        <criteria operator="AND" comment="IE7/XP x86/x64">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21183" test_ref="oval:org.mitre.oval:tst:11207"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16981" test_ref="oval:org.mitre.oval:tst:11559"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21183" test_ref="oval:org.mitre.oval:tst:11207"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16982" test_ref="oval:org.mitre.oval:tst:20566"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21184" test_ref="oval:org.mitre.oval:tst:21091"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.16000" test_ref="oval:org.mitre.oval:tst:9444"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.18385" test_ref="oval:org.mitre.oval:tst:11423"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.22585" test_ref="oval:org.mitre.oval:tst:11500"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.18000" test_ref="oval:org.mitre.oval:tst:10094"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.18167" test_ref="oval:org.mitre.oval:tst:11846"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.22290" test_ref="oval:org.mitre.oval:tst:11562"/>
        </criteria>
        <criteria operator="AND" comment="IE8/XP x86/x64, Server 2003 x86/x64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18876" test_ref="oval:org.mitre.oval:tst:11452"/>
        </criteria>
        <criteria operator="AND" comment="IE8/XP x86/x64, Server 2003 x86/x64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22967" test_ref="oval:org.mitre.oval:tst:11309"/>
        </criteria>
        <criteria operator="AND" comment="IE8/Vista x86/x64, Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18882" test_ref="oval:org.mitre.oval:tst:11541"/>
        </criteria>
        <criteria operator="AND" comment="IE8/Vista x86/x64, Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22973" test_ref="oval:org.mitre.oval:tst:11139"/>
        </criteria>
        <criteria operator="AND" comment="IE8/7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.16000" test_ref="oval:org.mitre.oval:tst:10787"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.16490" test_ref="oval:org.mitre.oval:tst:11780"/>
        </criteria>
        <criteria operator="AND" comment="IE8/7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:10804"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.20600" test_ref="oval:org.mitre.oval:tst:11312"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:82" version="2" class="vulnerability">
      <metadata>
        <title>Microsoft RPC Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft SQL Server 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0509" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0509"/>
        <description>Vulnerabilities in RPC servers in (1) Microsoft Exchange Server 2000 and earlier, (2) Microsoft SQL Server 2000 and earlier, (3) Windows NT 4.0, and (4) Windows 2000 allow remote attackers to cause a denial of service via malformed inputs.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-27T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2005-04-07T12:00:00.000-04:00" comment="modified wft-225 - correct literal component in file path. Added '\' to the start of the literal string.">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2005-04-11T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-04-12T12:00:00.000-04:00" comment="modified wft-89 - wft-89 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-27T12:07:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-27T01:26:00.000-04:00" comment="modified wft-89 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="SQL Server 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2977"/>
        <criterion comment="the version of ssmsrp70.dll is less than 2000.80.213.0" negate="false" test_ref="oval:org.mitre.oval:tst:2968"/>
        <criterion comment="the version of dbmsrpcn.dll is less than 2000.80.213.0" negate="false" test_ref="oval:org.mitre.oval:tst:2967"/>
        <criterion comment="File sqlservr.exe version3 greater than or equal to 2000.80.384.0" negate="true" test_ref="oval:org.mitre.oval:tst:2966"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8186" version="12" class="vulnerability">
      <metadata>
        <title>Uninitialized Memory Corruption Vulnerability (CVE-2010-0244)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0244" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0244"/>
        <description>Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-2530 and CVE-2009-2531.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-21T15:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-01-22T12:33:40.415-05:00">DRAFT</status_change>
            <modified comment="Updated to include tests for Windows XP SP2 (x86) running IE 7.  Microsoft bulletin MS10-002 (associated File Information article) did not include a reference to Windows XP SP2 (x86) running IE 7.0, though this is a vulnerable configuration and updated by the patch referenced in the article." date="2010-01-27T13:27:00.242-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2010-02-15T04:00:06.196-05:00">INTERIM</status_change>
            <status_change date="2010-03-08T04:00:11.792-05:00">ACCEPTED</status_change>
            <modified comment="Modified the mshtml.dll versions for IE8 on Windows 7 and Windows Server 2008 R2 in order to correctly identify the GDR and LDR branches." date="2010-05-11T13:38:00.735-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2010-05-11T13:41:04.760-04:00">INTERIM</status_change>
            <modified comment="Modified the mshtml.dll versions for IE8 on Windows 7 and Windows Server 2008 R2 in order to correctly identify the GDR and LDR branches." date="2010-05-11T13:41:00.299-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2010-05-31T04:00:43.542-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6932 - Updated comments to test ID's tst:10804 &amp; tst:10787. And also corrected the version to state ID's ste:6638 &amp; ste:6932 by adding comments according to the MS Bulletins." date="2011-07-18T15:25:00.211-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-07-18T15:26:43.866-04:00">INTERIM</status_change>
            <status_change date="2011-08-08T04:00:59.772-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:05.306-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:05.306-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:04:08.761-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:25:07.178-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:25.188-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8186 - extended definitions of OS are without SP checks" date="2014-07-28T17:37:00.435-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:39:28.907-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:32.815-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE6/Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1644" test_ref="oval:org.mitre.oval:tst:11530"/>
        </criteria>
        <criteria operator="AND" comment="IE6/XP">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3660" test_ref="oval:org.mitre.oval:tst:11697"/>
        </criteria>
        <criteria operator="AND" comment="IE6/XP">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5921" test_ref="oval:org.mitre.oval:tst:11468"/>
        </criteria>
        <criteria operator="AND" comment="IE6/XP x64/server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4639" test_ref="oval:org.mitre.oval:tst:11646"/>
        </criteria>
        <criteria operator="AND" comment="IE7/XP x86/x64">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16981" test_ref="oval:org.mitre.oval:tst:11559"/>
        </criteria>
        <criteria operator="AND" comment="IE7/XP x86/x64">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21183" test_ref="oval:org.mitre.oval:tst:11207"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16981" test_ref="oval:org.mitre.oval:tst:11559"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21183" test_ref="oval:org.mitre.oval:tst:11207"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16982" test_ref="oval:org.mitre.oval:tst:20566"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21184" test_ref="oval:org.mitre.oval:tst:21091"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.16000" test_ref="oval:org.mitre.oval:tst:9444"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.18385" test_ref="oval:org.mitre.oval:tst:11423"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.22585" test_ref="oval:org.mitre.oval:tst:11500"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.18000" test_ref="oval:org.mitre.oval:tst:10094"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.18167" test_ref="oval:org.mitre.oval:tst:11846"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.22290" test_ref="oval:org.mitre.oval:tst:11562"/>
        </criteria>
        <criteria operator="AND" comment="IE8/XP x86/x64, Server 2003 x86/x64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18876" test_ref="oval:org.mitre.oval:tst:11452"/>
        </criteria>
        <criteria operator="AND" comment="IE8/XP x86/x64, Server 2003 x86/x64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22967" test_ref="oval:org.mitre.oval:tst:11309"/>
        </criteria>
        <criteria operator="AND" comment="IE8/Vista x86/x64, Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18882" test_ref="oval:org.mitre.oval:tst:11541"/>
        </criteria>
        <criteria operator="AND" comment="IE8/Vista x86/x64, Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22973" test_ref="oval:org.mitre.oval:tst:11139"/>
        </criteria>
        <criteria operator="AND" comment="IE8/7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.16000" test_ref="oval:org.mitre.oval:tst:10787"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.16490" test_ref="oval:org.mitre.oval:tst:11780"/>
        </criteria>
        <criteria operator="AND" comment="IE8/7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:10804"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.20600" test_ref="oval:org.mitre.oval:tst:11312"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:816" version="6" class="vulnerability">
      <metadata>
        <title>COM+ Memory Structures Process Permits Remote Code Execution (Win2k,SP4)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1978" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1978"/>
        <description>COM+ in Microsoft Windows does not properly "create and use memory structures," which allows local users or remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-31T12:00:00.000-04:00" comment="removed an incorrect leading ^ from the value entity of ste:2402">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-31T00:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:54.237-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:816 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:06:39.310-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:03:32.111-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Windows 2000 is installed" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="Win2K/XP/2003 service pack 4 is installed" test_ref="oval:org.mitre.oval:tst:2569"/>
        <criteria operator="OR" comment="Either ole32.dll or rpcss.dll has a version less than 5.0.2195.7059">
          <criterion comment="the version of ole32.dll is less than 5.0.2195.7059" test_ref="oval:org.mitre.oval:tst:2568"/>
          <criterion comment="the version of rpcss.dll is less than 5.0.2195.7059" test_ref="oval:org.mitre.oval:tst:2567"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8127" version="5" class="vulnerability">
      <metadata>
        <title>Address Bar Spoofing on Double Byte Character Set Systems Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0844" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0844"/>
        <description>Internet Explorer 6 on Double Byte Character Set (DBCS) systems allows remote attackers to alter displayed address bars and spoof web pages via a URL containing special characters, facilitating phishing attacks, aka the "Address Bar Spoofing on Double Byte Character Set Systems Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-25T05:13:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-27T01:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-17T10:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-27T10:50:00.000-04:00" comment="modified wft-564 - Changed test to match comment">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:45:59.342-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:41:00.949-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:40.633-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:27.966-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1476" negate="false" test_ref="oval:org.mitre.oval:tst:856"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3534.2800" negate="true" test_ref="oval:org.mitre.oval:tst:519"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8080" version="2" class="vulnerability">
      <metadata>
        <title>Memory Corruption Vulnerability (CVE-2010-0805)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 5.01</product>
          <product>Microsoft Internet Explorer 6</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0805" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0805"/>
        <description>The Tabular Data Control (TDC) ActiveX control in Microsoft Internet Explorer 5.01 SP4, 6 on Windows XP SP2 and SP3, and 6 SP1 allows remote attackers to execute arbitrary code via a long URL (DataURL parameter) that triggers memory corruption in the CTDCCtl::SecurityCHeckDataURL function, aka "Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-30T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-03-31T14:15:27.688-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:13.080-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:59.234-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 5.01 Service Pack 4 on Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="Mshtml.dll version is less than 5.0.3886.1900" test_ref="oval:org.mitre.oval:tst:20983"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on Windows 2000 - RTMGDR">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1646" test_ref="oval:org.mitre.oval:tst:21144"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x86 SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3676" test_ref="oval:org.mitre.oval:tst:20926"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x86 SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5945" test_ref="oval:org.mitre.oval:tst:21222"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x64 SP2">
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4672" test_ref="oval:org.mitre.oval:tst:20919"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8064" version="3" class="vulnerability">
      <metadata>
        <title>DirectShow Heap Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0250" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0250"/>
        <description>Heap-based buffer overflow in DirectShow in Microsoft DirectX, as used in the AVI Filter on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2, and in Quartz on Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, allows remote attackers to execute arbitrary code via an AVI file with a crafted length field in an unspecified video stream, which is not properly handled by the RLE video decompressor, aka "DirectShow Heap Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-02-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-02-10T13:40:11.294-05:00">DRAFT</status_change>
            <status_change date="2010-03-01T04:00:14.814-05:00">INTERIM</status_change>
            <modified comment="Switched the version tests for Quartz.dll on Windows 2000; with DirectX 9.0x should be 6.5.1.913, without DirectX 9.0x should be 6.1.9.738" date="2010-03-12T14:20:00.051-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2010-05-17T04:01:11.304-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:08.634-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:08.634-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:04:07.764-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4 or later / AVI filter">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Avifil32.dll is less than 5.0.2195.7359" test_ref="oval:org.mitre.oval:tst:21095"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4 or later / Quartz">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Quartz.dll is less than 6.1.9.738" test_ref="oval:org.mitre.oval:tst:21059"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4 or later / Quartz in DirectX 9.0">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="DirectX 9.0x Installed" test_ref="oval:org.mitre.oval:tst:601"/>
          <criterion comment="the version of Quartz.dll is less than 6.5.1.913" test_ref="oval:org.mitre.oval:tst:20854"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2 / AVI filter">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="the version of Avifil32.dll is less than 5.1.2600.3649" test_ref="oval:org.mitre.oval:tst:20939"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2 / Quartz">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="the version of Quartz.dll is less than 6.5.2600.3649" test_ref="oval:org.mitre.oval:tst:21048"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3 / AVI filter">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of Avifil32.dll is less than 5.1.2600.5908" test_ref="oval:org.mitre.oval:tst:20757"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3 / Quartz">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of Quartz.dll is less than 6.5.2600.5908" test_ref="oval:org.mitre.oval:tst:20736"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2 / AVI filter">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of Avifil32.dll is less than 5.2.3790.4625" test_ref="oval:org.mitre.oval:tst:21066"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2 / Quartz">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of Quartz.dll is less than 6.5.3790.4625" test_ref="oval:org.mitre.oval:tst:21092"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - GDR / Quartz">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="the version of Quartz.dll is less than 6.6.6000.16986" test_ref="oval:org.mitre.oval:tst:20777"/>
          <criterion comment="the version of Quartz.dll is greater than or equal 6.6.6000.16000" test_ref="oval:org.mitre.oval:tst:20862"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - LDR / Quartz">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="the version of Quartz.dll is less than 6.6.6000.21188" test_ref="oval:org.mitre.oval:tst:21082"/>
          <criterion comment="the version of Quartz.dll is greater than or equal 6.6.6000.20000" test_ref="oval:org.mitre.oval:tst:21068"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - GDR / Quartz">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of Quartz.dll is less than 6.6.6001.18389" test_ref="oval:org.mitre.oval:tst:20105"/>
          <criterion comment="the version of Quartz.dll is greater than or equal 6.6.6001.18000" test_ref="oval:org.mitre.oval:tst:21070"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - LDR / Quartz">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of Quartz.dll is less than 6.6.6001.22590" test_ref="oval:org.mitre.oval:tst:20946"/>
          <criterion comment="the version of Quartz.dll is greater than or equal 6.6.6001.22000" test_ref="oval:org.mitre.oval:tst:20940"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - GDR / Quartz">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="the version of Quartz.dll is less than 6.6.6002.18158" test_ref="oval:org.mitre.oval:tst:20526"/>
          <criterion comment="the version of Quartz.dll is greater than or equal 6.6.6002.18000" test_ref="oval:org.mitre.oval:tst:20145"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - LDR / Quartz">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="the version of Quartz.dll is less than 6.6.6002.22295" test_ref="oval:org.mitre.oval:tst:20952"/>
          <criterion comment="the version of Quartz.dll is greater than or equal 6.6.6002.22000" test_ref="oval:org.mitre.oval:tst:20775"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - GDR / Quartz">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="the version of Quartz.dll is less than 6.6.7600.16490" test_ref="oval:org.mitre.oval:tst:20879"/>
          <criterion comment="the version of Quartz.dll is greater than or equal to 6.6.7600.16000" test_ref="oval:org.mitre.oval:tst:20619"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - LDR / Quartz">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="the version of Quartz.dll is less than 6.6.7600.20600" test_ref="oval:org.mitre.oval:tst:20804"/>
          <criterion comment="the version of Quartz.dll is greater than or equal to 6.6.7600.20000" test_ref="oval:org.mitre.oval:tst:20613"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8" version="3" class="vulnerability">
      <metadata>
        <title>SMB Rename Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference ref_id="CVE-2006-4696" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4696" source="CVE"/>
        <description>Unspecified vulnerability in the Server service in Microsoft Windows 2000 SP4, Server 2003 SP1 and earlier, and XP SP2 and earlier allows remote attackers to execute arbitrary code via a crafted packet, aka "SMB Rename Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-10-11T05:29:41">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-13T14:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-31T19:35:51.510-05:00">INTERIM</status_change>
            <status_change date="2006-11-21T21:28:02.463-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:8 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:06:07.062-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:47.938-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win2K,SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of srv.sys is less than 5.0.2195.7106" test_ref="oval:org.mitre.oval:tst:37"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP1">
          <extend_definition comment="Microsoft Windows XP SP1 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          <criterion comment="the version of srv.sys is less than 5.1.2600.1885" test_ref="oval:org.mitre.oval:tst:39"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of srv.sys is less than 5.1.2600.2974" test_ref="oval:org.mitre.oval:tst:111"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP1 (64-bit)">
          <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="the version of srv.sys is less than 5.2.3790.2783" test_ref="oval:org.mitre.oval:tst:40"/>
        </criteria>
        <criteria operator="AND" comment="S03-Gold">
          <extend_definition comment="Microsoft Windows Server 2003 (x86) Gold is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="the version of srv.sys is less than 5.2.3790.588" test_ref="oval:org.mitre.oval:tst:41"/>
        </criteria>
        <criteria operator="AND" comment="S03,SP1">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of srv.sys is less than 5.2.3790.2783" test_ref="oval:org.mitre.oval:tst:40"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:795" version="7" class="vulnerability" deprecated="true">
      <metadata>
        <title>DEPRECATED: Windows Script Engine Heap Overflow (Test 3)</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Windows Script Engine for JScript v5.5</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0010" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0010"/>
        <description>Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows operating system allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail that uses a large array index value that enables a heap-based buffer overflow attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2004-08-24T11:01:00.000-04:00" comment="Added patch information to definition">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-08-26T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-07-03T12:56:00.000-04:00" comment="Added negate=true attribute to criteria sub-block to fix conversion error from OVAL 4.2 to OVAL 5.0">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-07-03T12:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:38.925-04:00">ACCEPTED</status_change>
            <modified comment="Fixed regex in ste:2889.  Implemented by Matthew Wojcik." date="2007-03-06T18:19:00.507-05:00">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2007-03-06T18:21:13.852-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:28.063-04:00">ACCEPTED</status_change>
            <modified comment="Use def:134 instead, which covers all appropriate versions of windows and uses the file test" date="2011-01-20T10:36:25.174-05:00">
              <contributor organization="The MITRE Corporation">Nate Przybyszewski</contributor>
            </modified>
            <status_change date="2011-01-20T10:36:25.174-05:00">DEPRECATED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="the version of jscript.dll is less than 5.5.0.8513" negate="false" test_ref="oval:org.mitre.oval:tst:2906"/>
          <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed" negate="true">
            <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
            <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
          </criteria>
          <criterion comment="the patch js56nen.exe (5.5.0.8513 version) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2902"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="active scripting is enabled">
            <criteria operator="AND" comment="current user settings are being used and active scripting is enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and active scripting is enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:794" version="7" class="vulnerability" deprecated="true">
      <metadata>
        <title>DEPRECATED: Windows Script Engine Heap Overflow (Test 2)</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Windows Script Engine for JScript v5.1</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0010" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0010"/>
        <description>Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows operating system allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail that uses a large array index value that enables a heap-based buffer overflow attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2004-08-24T11:02:00.000-04:00" comment="Added patch information to definition">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-08-26T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-07-03T12:56:00.000-04:00" comment="Added negate=true attribute to criteria sub-block to fix conversion error from OVAL 4.2 to OVAL 5.0">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-07-03T12:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:53.836-04:00">ACCEPTED</status_change>
            <modified comment="Fixed regex in ste:2889.  Implemented by Matthew Wojcik." date="2007-03-06T18:19:00.507-05:00">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2007-03-06T18:21:14.535-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:27.797-04:00">ACCEPTED</status_change>
            <modified comment="Use def:134 instead, which covers all appropriate versions of windows and uses the file test" date="2011-01-20T10:35:34.539-05:00">
              <contributor organization="The MITRE Corporation">Nate Przybyszewski</contributor>
            </modified>
            <status_change date="2011-01-20T10:35:34.539-05:00">DEPRECATED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="the version of jscript.dll is less than 5.1.0.8513" negate="false" test_ref="oval:org.mitre.oval:tst:2907"/>
          <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed" negate="true">
            <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
            <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
          </criteria>
          <criterion comment="the patch js56nen.exe (5.1.0.8513 version) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2903"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="active scripting is enabled">
            <criteria operator="AND" comment="current user settings are being used and active scripting is enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and active scripting is enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7923" version="4" class="vulnerability">
      <metadata>
        <title>Apache 1.3 mod_proxy HTTP Chunked Encoding Integer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0010" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0010"/>
        <description>Integer overflow in the ap_proxy_send_fb function in proxy/proxy_util.c in mod_proxy in the Apache HTTP Server before 1.3.42 on 64-bit platforms allows remote origin servers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a large chunk size that triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-04T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-03-11T10:52:18.350-05:00">DRAFT</status_change>
            <modified comment="Added anchor to regular expression" date="2010-03-22T10:45:00.568-04:00">
              <contributor organization="The MITRE Corporation">Matt Hansbury</contributor>
            </modified>
            <modified comment="Added anchor to regular expression" date="2010-03-22T10:46:00.314-04:00">
              <contributor organization="The MITRE Corporation">Matt Hansbury</contributor>
            </modified>
            <status_change date="2010-05-17T04:01:08.770-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:55.740-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:3180 - new inventory for SQL Server 2008 R2 64-bit" date="2013-07-05T09:33:00.078-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-05T09:37:51.220-04:00">INTERIM</status_change>
            <status_change date="2013-07-22T04:03:15.186-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Windows 64 bit platform">
          <criterion comment="a version of Windows for the ia64 architecture is installed" test_ref="oval:org.mitre.oval:tst:2747"/>
          <criterion comment="a version of Windows for the x64 architecture is installed" test_ref="oval:org.mitre.oval:tst:3653"/>
        </criteria>
        <extend_definition comment="Apache HTTP Server 1.3.x is installed on the system" definition_ref="oval:org.mitre.oval:def:8565"/>
        <criterion comment="The version of Apache HTTP Server is less than 1.3.42" test_ref="oval:org.mitre.oval:tst:21143"/>
        <criterion comment="ApacheCore.dll exists" test_ref="oval:org.mitre.oval:tst:20505"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8565" version="4" class="inventory">
      <metadata>
        <title>Apache HTTP Server 1.3.x is installed on the system</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Apache</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:apache:http_server:1.3"/>
        <description>Apache HTTP Server 1.3.x is installed on the system</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-04T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-03-11T10:52:13.187-05:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:39.466-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:24.435-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:1436 - vulnerabilities for VMware and inventories for VMware Workstation, VMware View and VMware Player." date="2013-06-21T12:00:00.019-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-21T12:13:28.966-04:00">INTERIM</status_change>
            <status_change date="2013-07-08T04:03:01.221-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check for the Apache HTTP Server 1.3 installation." test_ref="oval:org.mitre.oval:tst:20454"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:792" version="9" class="vulnerability">
      <metadata>
        <title>IE6 Double Byte Character Parsing Memory Corruption (Win2K/WinXP)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1189" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1189"/>
        <description>Buffer overflow in URLMON.DLL in Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via a crafted URL with an International Domain Name (IDN) using double-byte character sets (DBCS), aka the "Double Byte Character Parsing Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added an anchor to the regex used to check for Internet Explorer 6." date="2007-01-11T20:38:00.950-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-01-11T20:49:15.998-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:59.745-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:2185 - Anchored regular expression" date="2011-02-22T12:51:00.261-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:52:33.453-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:25.770-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:44:32.225-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:03:30.801-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:45.230-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:27.594-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Win2K or XP,SP1 is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="Internet Explorer 6 (any patch level) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2333"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2800.1543" negate="false" test_ref="oval:org.mitre.oval:tst:2332"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:789" version="5" class="vulnerability">
      <metadata>
        <title>URL Parsing Memory Corruption Vulnerability (IE6,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0554" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0554"/>
        <description>Buffer overflow in the URL processor of Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a URL with a long hostname, aka "URL Parsing Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-05-11T05:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-06-23T12:49:00.000-04:00" comment="modified obj:1340 - Set xsi:nil to true on the name entity as we are only concerned with the existance of the key itself.">
              <contributor organization="Centennial Software">Jason Spashett</contributor>
            </modified>
            <status_change date="2006-06-23T12:49:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:38.339-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:46:03.185-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:58.863-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:43.183-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:27.309-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criteria operator="OR" comment="a vulnerable version of mshtml.dll exisits GDR/QFE">
            <criterion comment="machine has followed the GDR update path and mshtml.dll is less than 6.0.2800.1498" negate="false" test_ref="oval:org.mitre.oval:tst:2338"/>
            <criterion comment="machine has followed the QFE update path and mshtml.dll is less than 6.0.2800.1499" negate="false" test_ref="oval:org.mitre.oval:tst:2337"/>
          </criteria>
          <criterion comment="the patch kb890923 is installed (XP Win2K Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2336"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7865" version="4" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP3 Install Engine Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0216" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0216"/>
        <description>Integer overflow in the Install Engine (inseng.dll) for Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious website or HTML email with a long .CAB file name, which triggers the integer overflow when calculating a buffer length and leads to a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-25T04:20:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-27T01:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-17T10:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2824. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:48:00.494-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:52:29.108-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:58.563-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:47.566-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:27.240-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3015"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3821.2800" negate="false" test_ref="oval:org.mitre.oval:tst:625"/>
          <criterion comment="the patch kb834707-ie501sp3 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:624"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7840" version="6" class="vulnerability">
      <metadata>
        <title>Post Encoding Information Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Internet Explorer 5.01</product>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0488" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0488"/>
        <description>Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 does not properly handle unspecified "encoding strings," which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site, aka "Post Encoding Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-30T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-03-31T14:15:20.738-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:05.816-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:52.827-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:25:09.566-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:24.712-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7840 - extended definitions of OS are without SP checks" date="2014-07-28T17:37:00.435-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:39:31.656-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:32.477-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 5.01 Service Pack 4 on Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="Mshtml.dll version is less than 5.0.3886.1900" test_ref="oval:org.mitre.oval:tst:20983"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on Windows 2000 - RTMGDR">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1646" test_ref="oval:org.mitre.oval:tst:21144"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3676" test_ref="oval:org.mitre.oval:tst:20926"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5945" test_ref="oval:org.mitre.oval:tst:21222"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x64, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4672" test_ref="oval:org.mitre.oval:tst:20919"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on XP x86/x64 - GDR">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.17023" test_ref="oval:org.mitre.oval:tst:21218"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on XP x86/x64 - QFE">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21228" test_ref="oval:org.mitre.oval:tst:21283"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Server 2003 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.17023" test_ref="oval:org.mitre.oval:tst:21218"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Server 2003 x86/x64/ia64 - QFE">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21228" test_ref="oval:org.mitre.oval:tst:21283"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.17037" test_ref="oval:org.mitre.oval:tst:20820"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21242" test_ref="oval:org.mitre.oval:tst:21271"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.16000" test_ref="oval:org.mitre.oval:tst:9444"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.18444" test_ref="oval:org.mitre.oval:tst:20823"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.22653" test_ref="oval:org.mitre.oval:tst:21215"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.18000" test_ref="oval:org.mitre.oval:tst:10094"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.18226" test_ref="oval:org.mitre.oval:tst:21216"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.22360" test_ref="oval:org.mitre.oval:tst:21113"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:784" version="3" class="vulnerability">
      <metadata>
        <title>Windows 2000 Telnet Environment Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Services for UNIX</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1205" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1205"/>
        <description>The Telnet client for Microsoft Windows XP, Windows Server 2003, and Windows Services for UNIX allows remote attackers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-22T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2005-06-22T12:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:784 - Spelling mistakes fixed in def:784 and several author guide fixes." date="2011-05-02T19:05:00.614-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-02T19:05:59.269-04:00">INTERIM</status_change>
            <status_change date="2011-05-23T04:00:20.495-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Windows 2000 is installed" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion negate="true" comment="the patch KB896428 for Services for UNIX is installed" test_ref="oval:org.mitre.oval:tst:2351"/>
        <criteria operator="OR" comment="Services for UNIX is installed and a vulnerable version of telnet.exe exists">
          <criteria operator="AND" comment="Services for UNIX version 2.2 and telnet.exe version less than 5.3000.2073.13">
            <criterion comment="the version of telnet.exe is less than 5.3000.2073.13" test_ref="oval:org.mitre.oval:tst:2350"/>
            <criterion comment="the software Services for UNIX is installed and the version is 2.2" test_ref="oval:org.mitre.oval:tst:2349"/>
          </criteria>
          <criteria operator="AND" comment="Services for UNIX version 3.0 and telnet.exe version less than 7.0.1701.44">
            <criterion comment="the software Services for UNIX is installed and the version is 3.0" test_ref="oval:org.mitre.oval:tst:2348"/>
            <criterion comment="the version of telnet.exe is less than 7.0.1701.44" test_ref="oval:org.mitre.oval:tst:2347"/>
          </criteria>
          <criteria operator="AND" comment="Services for UNIX version 3.5 and telnet.exe version less than 8.0.1969.33">
            <criterion comment="the software Services for UNIX is installed and the version is 3.5" test_ref="oval:org.mitre.oval:tst:2346"/>
            <criterion comment="the version of telnet.exe is less than 8.0.1969.33" test_ref="oval:org.mitre.oval:tst:2345"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:78" version="7" class="vulnerability">
      <metadata>
        <title>Windows 2000 IIS Directory Traversal Command Execution (Test 1)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0333" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0333"/>
        <description>Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. (dot dot) and "\" characters twice.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2004-08-04T12:00:00.000-04:00" comment="Modifed without comment">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </modified>
            <status_change date="2004-08-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2004-08-26T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Multiple corrections and update to POSIX compatibility for ste:2884" date="2010-11-29T16:14:00.692-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-11-29T16:14:39.710-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:01:33.655-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:44:53.110-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:03:27.809-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="File %windir%\system32\inetsrv\ism.dll version is less than 5.0.2195.3407" negate="false" test_ref="oval:org.mitre.oval:tst:2971"/>
        <criterion comment="Patch Q293826 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3020"/>
        <criterion comment="Patch Q301625 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3037"/>
        <criterion comment="Patch Q319733 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3095"/>
        <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
        <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
        <criterion comment="Windows 2000 Security Roll-up 1 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2990"/>
        <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3079"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:778" version="7" class="vulnerability">
      <metadata>
        <title>LSASS Privilege Escalation Vulnerability (Windows 2000)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Local Security Authority Subsystem Service (LSASS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0894" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0894"/>
        <description>LSASS (Local Security Authority Subsystem Service) of Windows 2000 Server and Windows Server 2003 does not properly validate connection information, which allows local users to gain privileges via a specially-designed program.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-12-28T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-12T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-17T12:00:00.000-04:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2005-06-22T12:35:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected and tightened regular expression in ste:2610" date="2010-12-02T11:46:00.307-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-12-02T11:47:27.629-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:01:32.976-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:44:10.398-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:03:27.063-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 (sp4 or earlier) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 5 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2790"/>
        </criteria>
        <criterion comment="the version of lsasrv.dll is less than 5.0.2195.6987" negate="false" test_ref="oval:org.mitre.oval:tst:2357"/>
        <criterion comment="the patch kb885835is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2622"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7774" version="6" class="vulnerability">
      <metadata>
        <title>Race Condition Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Internet Explorer 5.01</product>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0489" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0489"/>
        <description>Race condition in Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via a crafted HTML document that triggers memory corruption, aka "Race Condition Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-30T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-03-31T14:15:21.533-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:03.030-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:50.043-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:25:00.890-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:24.426-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7774 - extended definitions of OS are without SP checks" date="2014-07-28T17:37:00.435-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:39:32.275-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:32.207-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 5.01 Service Pack 4 on Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="Mshtml.dll version is less than 5.0.3886.1900" test_ref="oval:org.mitre.oval:tst:20983"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on Windows 2000 - RTMGDR">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1646" test_ref="oval:org.mitre.oval:tst:21144"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3676" test_ref="oval:org.mitre.oval:tst:20926"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5945" test_ref="oval:org.mitre.oval:tst:21222"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x64, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4672" test_ref="oval:org.mitre.oval:tst:20919"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on XP x86/x64 - GDR">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.17023" test_ref="oval:org.mitre.oval:tst:21218"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on XP x86/x64 - QFE">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21228" test_ref="oval:org.mitre.oval:tst:21283"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Server 2003 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.17023" test_ref="oval:org.mitre.oval:tst:21218"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Server 2003 x86/x64/ia64 - QFE">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21228" test_ref="oval:org.mitre.oval:tst:21283"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.17037" test_ref="oval:org.mitre.oval:tst:20820"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21242" test_ref="oval:org.mitre.oval:tst:21271"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.16000" test_ref="oval:org.mitre.oval:tst:9444"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.18444" test_ref="oval:org.mitre.oval:tst:20823"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.22653" test_ref="oval:org.mitre.oval:tst:21215"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.18000" test_ref="oval:org.mitre.oval:tst:10094"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.18226" test_ref="oval:org.mitre.oval:tst:21216"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.22360" test_ref="oval:org.mitre.oval:tst:21113"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:777" version="6" class="vulnerability">
      <metadata>
        <title>Windows 2000 CSRSS Privilege Escalation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Client Server Runtime System (CSRSS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0551" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0551"/>
        <description>Stack-based buffer overflow in WINSRV.DLL in the Client Server Runtime System (CSRSS) process of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application that provides console window information with a long FaceName value.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-02T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2005-05-04T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-06-17T12:00:00.000-04:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2005-07-27T10:37:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected and tightened regular expression in ste:2610" date="2010-12-02T11:46:00.307-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-12-02T11:47:28.052-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:01:32.683-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:44:14.699-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:03:26.716-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 (sp4 or earlier) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 5 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2790"/>
        </criteria>
        <criterion comment="The version of Ntoskrnl.exe is less than 5.0.2195.7035" negate="false" test_ref="oval:org.mitre.oval:tst:2358"/>
        <criterion comment="the patch KB890859 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2737"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:776" version="4" class="vulnerability">
      <metadata>
        <title>IE5.01,SP4 File Disclosure via Redirects Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0648" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0648"/>
        <description>The legacy &lt;script> data-island capability for XML in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to read arbitrary XML files, and portions of other files, via a URL whose "src" attribute redirects to a local file.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-22T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-06-22T12:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed ste:2614: set datatype to version.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:54:00.319-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:59:40.296-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:57.997-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:41.291-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:27.096-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3828.2700" negate="false" test_ref="oval:org.mitre.oval:tst:2359"/>
          <criterion comment="the patch kb883939 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2750"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7751" version="3" class="vulnerability">
      <metadata>
        <title>SMB NTLM Authentication Lack of Entropy Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0231" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0231"/>
        <description>The SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not use a sufficient source of entropy, which allows remote attackers to obtain access to files and other SMB resources via a large number of authentication requests, related to server-generated challenges, certain "duplicate values," and spoofing of an authentication token, aka "SMB NTLM Authentication Lack of Entropy Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-02-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-02-10T13:39:56.561-05:00">DRAFT</status_change>
            <status_change date="2010-03-01T04:00:12.404-05:00">INTERIM</status_change>
            <status_change date="2010-03-22T04:00:05.057-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:59.806-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:59.806-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:04:06.355-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4 or later">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Srv.sys version is less than 5.0.2195.7365" test_ref="oval:org.mitre.oval:tst:21057"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="Srv.sys version is less than 5.1.2600.3662" test_ref="oval:org.mitre.oval:tst:20948"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Srv.sys version is less than 5.1.2600.5923" test_ref="oval:org.mitre.oval:tst:21069"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="Srv.sys version is less than 5.2.3790.4634" test_ref="oval:org.mitre.oval:tst:21015"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9543"/>
          <criterion comment="Srv.sys version is less than 6.0.6000.16977" test_ref="oval:org.mitre.oval:tst:20632"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:8674"/>
          <criterion comment="Srv.sys version is less than 6.0.6000.21179" test_ref="oval:org.mitre.oval:tst:21047"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9601"/>
          <criterion comment="Srv.sys version is less than 6.0.6001.18381" test_ref="oval:org.mitre.oval:tst:20390"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9666"/>
          <criterion comment="Srv.sys version is less than 6.0.6001.22581" test_ref="oval:org.mitre.oval:tst:21064"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6002.18000" test_ref="oval:org.mitre.oval:tst:20868"/>
          <criterion comment="Srv.sys version is less than 6.0.6002.18164" test_ref="oval:org.mitre.oval:tst:20904"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:21089"/>
          <criterion comment="Srv.sys version is less than 6.0.6002.22286" test_ref="oval:org.mitre.oval:tst:20763"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.1.7600.16000" test_ref="oval:org.mitre.oval:tst:20615"/>
          <criterion comment="Srv.sys version is less than 6.1.7600.16481" test_ref="oval:org.mitre.oval:tst:21084"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:20704"/>
          <criterion comment="Srv.sys version is less than 6.1.7600.20591" test_ref="oval:org.mitre.oval:tst:21034"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:775" version="2" class="vulnerability">
      <metadata>
        <title>Microsoft Data Access Components 2.8 Broadcast Response Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Data Access Components 2.8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0903" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0903"/>
        <description>Buffer overflow in a component of Microsoft Data Access Components (MDAC) 2.5 through 2.8 allows remote attackers to execute arbitrary code via a malformed UDP response to a broadcast request.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.717-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-10-25T16:57:27.176-04:00">INTERIM</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.882-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-11-13T12:01:21.491-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Microsoft Data Access Components 2.8 (RTM) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2363"/>
        <criterion comment="the version of odbcbcp.dll is less than 2000.85.1025.0" negate="false" test_ref="oval:org.mitre.oval:tst:2362"/>
        <criterion comment="the version of sqlsrv32.dll is less than 2000.85.1025.0" negate="false" test_ref="oval:org.mitre.oval:tst:2361"/>
        <criteria operator="OR" comment="the patch q832483 is not installed">
          <criteria operator="AND" comment="32-bit edition of windows and patch q832483 is not installed">
            <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            <criterion comment="the patch q832483 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2573"/>
          </criteria>
          <criteria operator="AND" comment="64-bit edition of windows and patch q832483 is not installed">
            <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            <criterion comment="the patch q832483 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2360"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:774" version="5" class="vulnerability">
      <metadata>
        <title>IE v6.0,SP1 Travel Log Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1026" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1026"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:52:00.000-04:00" comment="modified wft-94 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:46:07.285-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:57.688-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:41.144-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:27.027-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1400" negate="false" test_ref="oval:org.mitre.oval:tst:2579"/>
          <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:770" version="5" class="vulnerability">
      <metadata>
        <title>IE6,SP1 PNG Image Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1211" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1211"/>
        <description>Buffer overflow in the PNG image rendering component of Microsoft Internet Explorer allows remote attackers to execute arbitrary code via a crafted PNG file.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-22T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-06-22T09:24:00.000-04:00">DRAFT</status_change>
            <modified date="2005-06-24T12:00:00.000-04:00" comment="added description">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-17T04:13:00.000-04:00" comment="Fixed registry_object obj:1557 by moving PNGFilter.CoPNGFilter from name to end of key, and setting xsi:nil to true on name.  Modified by Harvey Rubinovitz">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2006-10-17T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-11-14T08:57:58.160-05:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:46:05.785-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:56.830-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:41.083-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:26.832-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criteria operator="OR" comment="the version of mshtml.dll is less than 6.0.2800.1505 or 6.0.2800.1506">
            <criterion comment="the version of mshtml.dll is less than 6.0.2800.1505 (RTMGDR)" negate="false" test_ref="oval:org.mitre.oval:tst:2365"/>
            <criterion comment="the version of mshtml.dll is less than 6.0.2800.1506 (RTMQFE)" negate="false" test_ref="oval:org.mitre.oval:tst:2364"/>
          </criteria>
          <criterion comment="the patch kb883939 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2750"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="PNG image rendering enabled in Internet Explorer" negate="false" test_ref="oval:org.mitre.oval:tst:2749"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:77" version="3" class="vulnerability">
      <metadata>
        <title>IE v5.5 GetObject File Retrieval</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0023" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0023"/>
        <description>Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to read arbitrary files via malformed requests to the GetObject function, which bypass some of GetObject's security checks.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:57.088-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:26.783-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Internet Explorer 5.5 Installed">
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3078"/>
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3077"/>
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3076"/>
        </criteria>
        <criterion comment="the version of mshtml.dll is less than 5.50.4725.2100" negate="false" test_ref="oval:org.mitre.oval:tst:3075"/>
        <criterion comment="the patch q316059 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3121"/>
        <criterion comment="the patch q319282 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3120"/>
        <criterion comment="the patch q321232 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3119"/>
        <criterion comment="the patch q323759 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3118"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:762" version="4" class="vulnerability">
      <metadata>
        <title>MS FrontPage Server Extensions SmartHTML Denial of Service (Test 5)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft SharePoint Team Services</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0824" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0824"/>
        <description>Unknown vulnerability in the SmartHTML interpreter (shtml.dll) in Microsoft FrontPage Server Extensions 2000 and 2002, and Microsoft SharePoint Team Services 2002, allows remote attackers to cause a denial of service (response failure) via a certain request.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-12-09T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-14T12:00:00.000-04:00" comment="Changed the definition to look at the file shtml.dll instead of fp5awel.dll.  It was determined that this is where the vulnerability (a buffer overflow) actually existed.  Also added the configuration test saying you are vulnerable if the SmartHTML interpreter is enabled.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2004-09-14T09:53:00.000-04:00" comment="XP SP2 added">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-09-15T12:00:00.000-04:00">INTERIM</status_change>
            <modified comment="Corrected to use a forward slash as the separator in the key." date="2007-05-07T15:59:00.964-04:00">
              <contributor organization="Secure Elements, Inc.">Glenn Strickland</contributor>
            </modified>
            <modified comment="Multiple corrections and update to POSIX compatibility for ste:2656" date="2010-11-29T16:12:00.873-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Software section">
          <criteria operator="OR" comment="Windows 2000, XP, or 2003 is installed">
            <criterion comment="Windows 2000 is installed" test_ref="oval:org.mitre.oval:tst:3085"/>
            <criterion comment="Windows XP is installed" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="Windows Server 2003 is installed" test_ref="oval:org.mitre.oval:tst:2761"/>
          </criteria>
          <criterion comment="a vulnerable version of shtml.dll exists (FPSE 2002 or SPTS 2003)" test_ref="oval:org.mitre.oval:tst:2490"/>
          <criterion negate="true" comment="Win2K/XP/2003 service pack 2 (or later) is installed" test_ref="oval:org.mitre.oval:tst:2837"/>
        </criteria>
        <criteria operator="AND" comment="Configuration section">
          <criterion comment="SharePoint Team Services are enabled (2K, XP, 2003)" test_ref="oval:org.mitre.oval:tst:2379"/>
          <criterion comment="SmartHTML interpreter is enabled" test_ref="oval:org.mitre.oval:tst:2705"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7611" version="6" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP3 SSL Cached Content Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0845" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0845"/>
        <description>Internet Explorer 5.01, 5.5, and 6 does not properly cache SSL content, which allows remote attackers to obtain information or spoof content via a web site with the same host name as the target web site, whose content is cached and reused when the user visits the target web site.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-26T02:09:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-27T01:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-17T10:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-06-23T12:49:00.000-04:00" comment="modified obj:490 - Chagned the pattern match operation to equals since there was no need for a regular expression.">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-06-23T11:35:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:37.703-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2824. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:48:00.494-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:52:26.101-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:56.374-05:00">ACCEPTED</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.853-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-10-25T16:53:30.999-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:01:21.209-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:36.228-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:26.721-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3015"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3821.2800" negate="false" test_ref="oval:org.mitre.oval:tst:625"/>
          <criterion comment="the patch kb834707-ie501sp3 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:624"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Users not saving encrypted pages to disk  (DisableCachingOfSSLPages)" negate="false" test_ref="oval:org.mitre.oval:tst:588"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:761" version="7" class="vulnerability">
      <metadata>
        <title>Script Error Handling Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5579" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5579"/>
        <description>Microsoft Internet Explorer 6 allows remote attackers to execute arbitrary code by using JavaScript to cause certain errors simultaneously, which results in the access of previously freed memory, aka "Script Error Handling Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-12-13T08:17:04">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-12-14T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:54:01.277-05:00">INTERIM</status_change>
            <modified comment="Added an anchor to the regex used to check for Internet Explorer 6." date="2007-01-11T20:38:00.950-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-20T13:40:56.052-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:2185 - Anchored regular expression" date="2011-02-22T12:51:00.261-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:52:32.653-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:25.330-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:39.473-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:26.620-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:132 - Addressed validation errors and duplicate extended definitions" date="2015-07-13T20:21:00.869-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:25:22.982-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:02:08.364-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Server 2003-Gold">
          <extend_definition comment="Microsoft Windows Server 2003 (x86) Gold is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.605" test_ref="oval:org.mitre.oval:tst:92"/>
        </criteria>
        <criteria comment="XP,SP1 (64-bit) and Server 2003, SP1">
          <criteria operator="OR" comment="Windows XP (64-bit,SP1) or Server 2003 (SP1) is installed">
            <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2817" test_ref="oval:org.mitre.oval:tst:90"/>
        </criteria>
        <criteria comment="IE 6 on Windows XP,SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3020" test_ref="oval:org.mitre.oval:tst:132"/>
        </criteria>
        <criteria comment="IE 6 on Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1586" test_ref="oval:org.mitre.oval:tst:89"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7609" version="7" class="vulnerability">
      <metadata>
        <title>Win32k Improper Data Validation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0484" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0484"/>
        <description>The Windows kernel-mode drivers in win32k.sys in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2 "do not properly validate changes in certain kernel objects," which allows local users to execute arbitrary code via vectors related to Device Contexts (DC) and the GetDCEx function, aka "Win32k Improper Data Validation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-06-14T11:31:22.522-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:50:05.413-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:54.866-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7609 - Modified GDR/LDR service branch format to read easier, removed duplicate, and updated extended def for Vista." date="2011-01-31T15:31:00.891-05:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-01-31T15:32:14.712-05:00">INTERIM</status_change>
            <status_change date="2011-02-21T04:01:14.290-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5160 - contains tests with modified comments and all dependences" date="2014-02-13T12:19:00.287-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:23:05.202-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:24.158-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of win32k.sys is less than 5.0.2195.7397" test_ref="oval:org.mitre.oval:tst:27601"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="the version of win32k.sys is less than 5.1.2600.3706" test_ref="oval:org.mitre.oval:tst:27275"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of win32k.sys is less than 5.1.2600.5976" test_ref="oval:org.mitre.oval:tst:27640"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of win32k.sys is less than 5.2.3790.4702" test_ref="oval:org.mitre.oval:tst:27693"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Vista x86/x64 SP1, all Server 2008 x86/x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of win32k.sys is less than 6.0.6001.18468" test_ref="oval:org.mitre.oval:tst:27353"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of win32k.sys is less than 6.0.6001.22682" test_ref="oval:org.mitre.oval:tst:27380"/>
              <criterion comment="the version of win32k.sys is greater than 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:10142"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Vista x86/x64 SP2, Server 2008 x86/64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of win32k.sys is less than 6.0.6002.18253" test_ref="oval:org.mitre.oval:tst:27138"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of win32k.sys is less than 6.0.6002.22396" test_ref="oval:org.mitre.oval:tst:27022"/>
              <criterion comment="the version of win32k.sys is greater than 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10124"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:76" version="6" class="vulnerability">
      <metadata>
        <title>Windows 2000 Process Handle Duplication Privilege Escalation</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0367" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0367"/>
        <description>smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as demonstrated by DebPloit.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-04-04T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified comment="Multiple corrections and update to POSIX compatibility for ste:2884" date="2010-11-29T16:14:00.692-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-11-29T16:14:39.349-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:01:32.417-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:44:51.849-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:03:26.169-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="File %windir%\system32\smss.exe version is less than 5.0.2195.5695" negate="false" test_ref="oval:org.mitre.oval:tst:2973"/>
        <criterion comment="Patch Q320206 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2972"/>
        <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3079"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7569" version="8" class="vulnerability">
      <metadata>
        <title>WinINet and Windows HTTP Services Credential Reflection Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0550" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0550"/>
        <description>Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008; and WinINet in Microsoft Internet Explorer 5.01 SP4, 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on Windows Server 2003 SP1 and SP2, 7 on Windows Vista Gold and SP1, and 7 on Windows Server 2008; allows remote web servers to capture and replay NTLM credentials, and execute arbitrary code, via vectors related to absence of a "credential-reflection protections" opt-in step, aka "Windows HTTP Services Credential Reflection Vulnerability" and "WinINet Credential Reflection Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-26T17:00:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-01-03T21:03:03.385-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:01:05.787-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:44.710-05:00">ACCEPTED</status_change>
            <modified comment="Edited var:306 - Added beginning anchor to local_variable used in pattern match" date="2010-05-13T15:50:00.065-04:00">
              <contributor organization="The MITRE Corporation">Mike Lah</contributor>
            </modified>
            <status_change date="2010-05-13T15:50:58.469-04:00">INTERIM</status_change>
            <status_change date="2010-05-31T04:00:37.438-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:306 - Added closing anchors for variable regex" date="2013-04-08T11:01:00.574-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-04-08T11:03:34.530-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:17:48.896-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7569 - extended definitions of OS are without SP checks" date="2014-07-28T17:34:00.316-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:36:12.409-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:30.302-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE5/Microsoft Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="Mshtml.dll version is less than 5.0.3874.1900" test_ref="oval:org.mitre.oval:tst:9783"/>
        </criteria>
        <criteria operator="AND" comment="IE6/Microsoft Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1625" test_ref="oval:org.mitre.oval:tst:9684"/>
        </criteria>
        <criteria operator="AND" comment="IE6/Microsoft Windows XP">
          <extend_definition comment="Microsoft Windows XP is installed" definition_ref="oval:org.mitre.oval:def:105"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3527" test_ref="oval:org.mitre.oval:tst:9744"/>
        </criteria>
        <criteria operator="AND" comment="IE6/Microsoft Windows XP (32-bit)">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5764" test_ref="oval:org.mitre.oval:tst:9622"/>
        </criteria>
        <criteria operator="AND" comment="IE6/Microsoft Server 2003 (32-bit)">
          <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.3304" test_ref="oval:org.mitre.oval:tst:9395"/>
        </criteria>
        <criteria operator="AND" comment="IE6/Microsoft Server 2003 (32-bit)">
          <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4470" test_ref="oval:org.mitre.oval:tst:9788"/>
        </criteria>
        <criteria operator="AND" comment="IE6/XP x64/Server 2003 x64">
          <criteria operator="OR" comment="XP x64/Server 2003 x64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.3304" test_ref="oval:org.mitre.oval:tst:9395"/>
        </criteria>
        <criteria operator="AND" comment="IE6/XP x64/Server 2003 x64">
          <criteria operator="OR" comment="XP x64/Server 2003 x64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4470" test_ref="oval:org.mitre.oval:tst:9788"/>
        </criteria>
        <criteria operator="AND" comment="IE6/Server 2003 ia64">
          <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.3304" test_ref="oval:org.mitre.oval:tst:9395"/>
        </criteria>
        <criteria operator="AND" comment="IE6/Server 2003 ia64">
          <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4470" test_ref="oval:org.mitre.oval:tst:9788"/>
        </criteria>
        <criteria operator="AND" comment="IE7/XP x86/x64">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16825" test_ref="oval:org.mitre.oval:tst:9976"/>
        </criteria>
        <criteria operator="AND" comment="IE7/XP x86/x64">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21015" test_ref="oval:org.mitre.oval:tst:9705"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16825" test_ref="oval:org.mitre.oval:tst:9976"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21015" test_ref="oval:org.mitre.oval:tst:9705"/>
        </criteria>
        <criteria operator="AND" comment="Mshtml.dll/Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16830" test_ref="oval:org.mitre.oval:tst:9688"/>
        </criteria>
        <criteria operator="AND" comment="Mshtml.dll/Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21023" test_ref="oval:org.mitre.oval:tst:10115"/>
        </criteria>
        <criteria operator="AND" comment="Mshtml.dll/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.16000" test_ref="oval:org.mitre.oval:tst:9444"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.18226" test_ref="oval:org.mitre.oval:tst:10150"/>
        </criteria>
        <criteria operator="AND" comment="Mshtml.dll/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.22389" test_ref="oval:org.mitre.oval:tst:10005"/>
        </criteria>
        <criteria operator="AND" comment="winhttp.dll version 5.1.2600.3490 or later on Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <criterion comment="system32\winhttp.dll version less than 5.1.2600.3490" test_ref="oval:org.mitre.oval:tst:9822"/>
        </criteria>
        <criteria operator="AND" comment="winhttp.dll versin 5.1.2600.3494 or later on Windows XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="system32\winhttp.dll version less than 5.1.2600.3494" test_ref="oval:org.mitre.oval:tst:9877"/>
        </criteria>
        <criteria operator="AND" comment="winhttp.dll versin 5.1.2600.5727 or later on Windows XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="system32\winhttp.dll version less than 5.1.2600.5727" test_ref="oval:org.mitre.oval:tst:9540"/>
        </criteria>
        <criteria operator="AND" comment="winhttp.dll versin 5.2.3790.3262 or later on Windows XP x64">
          <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          <criterion comment="system32\winhttp.dll version less than 5.2.3790.3262" test_ref="oval:org.mitre.oval:tst:9795"/>
        </criteria>
        <criteria operator="AND" comment="winhttp.dll versin 5.2.3790.4427 or later on Windows XP x64">
          <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          <criterion comment="system32\winhttp.dll version less than 5.2.3790.4427" test_ref="oval:org.mitre.oval:tst:9649"/>
        </criteria>
        <criteria operator="AND" comment="winhttp.dll versin 5.2.3790.3262 or later on windows server 2003 (x86)(x64)(ia64)">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <criterion comment="Winsxs\winhttp.dll version less than 5.2.3790.3262" test_ref="oval:org.mitre.oval:tst:9580"/>
        </criteria>
        <criteria operator="AND" comment="winhttp.dll versin 5.2.3790.4427 or later on windows server 2003 (x86)(x64)(ia64)">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <criterion comment="Winsxs\winhttp.dll version less than 5.2.3790.4427" test_ref="oval:org.mitre.oval:tst:9985"/>
        </criteria>
        <criteria operator="AND" comment="winhttp.dll versin 6.0.6000.16786 or later on windows vista GDR (x86)(x64)">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="system32\winhttp.dll version greater than or equal 6.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9951"/>
          <criterion comment="system32\winhttp.dll version less than 6.0.6000.16786" test_ref="oval:org.mitre.oval:tst:9981"/>
        </criteria>
        <criteria operator="AND" comment="winhttp.dll versin 6.0.6000.20971 or later on windows vista LDR (x86)(x64)">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="system32\winhttp.dll version greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9442"/>
          <criterion comment="system32\winhttp.dll version less than 6.0.6000.20971" test_ref="oval:org.mitre.oval:tst:9594"/>
        </criteria>
        <criteria operator="AND" comment="winhttp.dll versin 6.0.6001.18178 or later on windows server 2008 sp1 GDR (x86)(x64)(ia64) and windows vista sp1 GDR (x86)(x64)">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="system32\winhttp.dll version greater than or equal 6.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9762"/>
          <criterion comment="system32\winhttp.dll version less than 6.0.6001.18178" test_ref="oval:org.mitre.oval:tst:9801"/>
        </criteria>
        <criteria operator="AND" comment="winhttp.dll versin 6.0.6001.22323 or later on windows server 2008 sp1 LDR (x86)(x64)(ia64) and windows vista sp1 GDR (x86)(x64)">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="system32\winhttp.dll version greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9825"/>
          <criterion comment="system32\winhttp.dll version less than 6.0.6001.22323" test_ref="oval:org.mitre.oval:tst:9119"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:751" version="2" class="vulnerability">
      <metadata>
        <title>Microsoft Data Access Components 2.7 Broadcast Response Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Data Access Components 2.7</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0903" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0903"/>
        <description>Buffer overflow in a component of Microsoft Data Access Components (MDAC) 2.5 through 2.8 allows remote attackers to execute arbitrary code via a malformed UDP response to a broadcast request.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.717-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-10-25T16:57:27.527-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:01:20.986-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Microsoft Data Access Components 2.7 is installed and a vulnerable version of sqlsrv32.dll and odbcbcp.dll exists">
          <criteria operator="AND" comment="Microsoft Data Access Components 2.7 (RTM) is installed and both sqlsrv32.dll and odbcbcp.dll are less than 2000.81.9002.0">
            <criterion comment="Microsoft Data Access Components 2.7 (RTM) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2590"/>
            <criterion comment="the version of sqlsrv32.dll is less than 2000.81.9002.0" negate="false" test_ref="oval:org.mitre.oval:tst:2384"/>
            <criterion comment="the version of odbcbcp.dll is less than 2000.81.9002.0" negate="false" test_ref="oval:org.mitre.oval:tst:2383"/>
          </criteria>
          <criteria operator="AND" comment="Microsoft Data Access Components 2.7 (SP1) is installed and both sqlsrv32.dll and odbcbcp.dll are less than 2000.81.9042.0">
            <criterion comment="Microsoft Data Access Components 2.7 (SP1) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2382"/>
            <criterion comment="the version of sqlsrv32.dll is less than 2000.81.9042.0" negate="false" test_ref="oval:org.mitre.oval:tst:2381"/>
            <criterion comment="the version of odbcbcp.dll is less than 2000.81.9042.0" negate="false" test_ref="oval:org.mitre.oval:tst:2380"/>
          </criteria>
        </criteria>
        <criterion comment="the patch q832483 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2573"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7509" version="3" class="vulnerability">
      <metadata>
        <title>Windows Kernel Symbolic Link Value Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0235" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0235"/>
        <description>The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Vista Gold does not perform the expected validation before creating a symbolic link, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Symbolic Link Value Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-13T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-04-15T10:42:26.708-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:54.837-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:41.581-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4 or later">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 5.0.2195.7376" test_ref="oval:org.mitre.oval:tst:11458"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 5.1.2600.3670" test_ref="oval:org.mitre.oval:tst:11347"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 5.1.2600.5938" test_ref="oval:org.mitre.oval:tst:11896"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is less than 5.2.3790.4666" test_ref="oval:org.mitre.oval:tst:11857"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Server 2003 ia64 SP2">
          <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          <criterion comment="The version of Ntkrnlmp.exe is less than 5.2.3790.4666" test_ref="oval:org.mitre.oval:tst:11611"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6000.16000" test_ref="oval:org.mitre.oval:tst:10882"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6000.17021" test_ref="oval:org.mitre.oval:tst:11259"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:10762"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6000.21226" test_ref="oval:org.mitre.oval:tst:11841"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:747" version="3" class="vulnerability">
      <metadata>
        <title>Winsock Hostname Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference ref_id="CVE-2006-3440" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3440" source="CVE"/>
        <description>Buffer overflow in the Winsock API in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via unknown vectors, aka "Winsock Hostname Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:37.143-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:48.747-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:747 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:05:18.747-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:47.560-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win2K,SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="The version of dnsapi.dll is less than 5.0.2195.7100." test_ref="oval:org.mitre.oval:tst:130"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP1">
          <extend_definition comment="Microsoft Windows XP SP1 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          <criterion comment="The version of dnsapi.dll is less than 5.1.2600.1863." test_ref="oval:org.mitre.oval:tst:81"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="The version of dnsapi.dll is less than 5.1.2600.2938." test_ref="oval:org.mitre.oval:tst:198"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP1 (64-bit)">
          <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="The version of dnsapi.dll is less than 5.2.3790.2745." test_ref="oval:org.mitre.oval:tst:51"/>
        </criteria>
        <criteria operator="AND" comment="S03-Gold">
          <extend_definition comment="Microsoft Windows Server 2003 (x86) Gold is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="The version of dnsapi.dll is less than 5.2.3790.558." test_ref="oval:org.mitre.oval:tst:159"/>
        </criteria>
        <criteria operator="AND" comment="S03,SP1">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="The version of dnsapi.dll is less than 5.2.3790.2745." test_ref="oval:org.mitre.oval:tst:51"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7448" version="6" class="vulnerability">
      <metadata>
        <title>IE v5.5,SP2 Similar Method Name Redirection Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0727" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0727"/>
        <description>Microsoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows remote web servers to bypass zone restrictions and execute arbitrary code in the local computer zone by redirecting a function to another function with the same name, as demonstrated by SimilarMethodNameRedir, aka the "Similar Method Name Redirection Cross Domain Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-19T07:31:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-20T02:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:42:00.000-04:00" comment="modified wft-562 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-14T11:27:00.000-04:00" comment="Fixed CVE reference; was CVE-2003-0727 because of a typo.  Now correctly refers to CVE-2004-0727.  Change was implemented by Matthew Wojcik.">
              <contributor organization="MessageLabs">Andrew Simmons</contributor>
            </modified>
            <status_change date="2005-12-16T12:49:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added platforms based on MS Bulletin information." date="2008-06-27T09:26:00.268-04:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2008-06-27T09:44:31.282-04:00">INTERIM</status_change>
            <status_change date="2008-07-14T04:00:23.150-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:59.188-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:26.407-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
          <criterion comment="the version of mshtml.dll is less than 5.50.4945.2800" negate="false" test_ref="oval:org.mitre.oval:tst:384"/>
          <criterion comment="the patch kb834707 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:855"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:743" version="6" class="vulnerability">
      <metadata>
        <title>MS FrontPage Server Extensions Chunked Encoded Request Buffer Overflow (Test 5)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft FrontPage Server Extensions 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0822" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0822"/>
        <description>Buffer overflow in the debug functionality in fp30reg.dll of Microsoft FrontPage Server Extensions (FPSE) 2000 and 2002 allows remote attackers to execute arbitrary code via a crafted chunked encoded request.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-03-04T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2003-03-05T12:00:00.000-04:00" comment="Changed the definition to test for fp30reg.dll and fp4areg.dll instead of fp4awel.dll.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T10:50:00.000-04:00" comment="modified wft-114 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-09-27T01:22:00.000-04:00" comment="modified wft-31 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed regex in ste:2889.  Implemented by Matthew Wojcik." date="2007-03-06T18:19:00.507-05:00">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2007-03-06T18:21:14.792-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:26.161-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:44:41.402-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:03:25.346-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows 2000 (sp3 or earlier) is installed">
            <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
            <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3084"/>
          </criteria>
          <criteria operator="OR" comment="a vulnerable version of fp30reg.dll or fp4areg.dll exists">
            <criterion comment="the version of fp4areg.dll is less than 4.0.02.7523" negate="false" test_ref="oval:org.mitre.oval:tst:2681"/>
            <criterion comment="the version of fp30reg.dll is less than 4.00.02.7523" negate="false" test_ref="oval:org.mitre.oval:tst:2680"/>
          </criteria>
          <criterion comment="the patch q810217 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2707"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="FrontPage Server Extensions 2000 are enabled (2K, XP)" negate="false" test_ref="oval:org.mitre.oval:tst:2706"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7406" version="11" class="vulnerability">
      <metadata>
        <title>Memory Corruption Vulnerability (CVE-2010-1262)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1262" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1262"/>
        <description>Microsoft Internet Explorer 6 SP1 and SP2, 7, and 8 allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, related to the CStyleSheet object and a free of the root container, aka "Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-06-14T11:32:19.562-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:49.906-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:45.468-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:10804 - Updated comments to test ID's tst:10804 &amp; tst:10787. And also corrected the version to state ID's ste:6638 &amp; ste:6932 by adding comments according to the MS Bulletins." date="2011-07-18T15:25:00.211-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-07-18T15:27:13.824-04:00">INTERIM</status_change>
            <status_change date="2011-08-08T04:00:57.305-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:02.290-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:02.290-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:57.658-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:25:12.822-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:22.250-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7406 - extended definitions of OS are without SP checks" date="2014-07-28T17:37:00.435-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:39:31.978-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:27.432-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 6 on Windows 2000 - RTMGDR">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1649" test_ref="oval:org.mitre.oval:tst:27761"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3698" test_ref="oval:org.mitre.oval:tst:27446"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5969" test_ref="oval:org.mitre.oval:tst:27626"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x64, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4696" test_ref="oval:org.mitre.oval:tst:27176"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on XP x86/x64 - GDR">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.17063" test_ref="oval:org.mitre.oval:tst:27760"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on XP x86/x64 - QFE">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21264" test_ref="oval:org.mitre.oval:tst:27363"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Server 2003 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.17063" test_ref="oval:org.mitre.oval:tst:27760"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Server 2003 x86/x64/ia64 - QFE">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21264" test_ref="oval:org.mitre.oval:tst:27363"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.18470" test_ref="oval:org.mitre.oval:tst:27673"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.22685" test_ref="oval:org.mitre.oval:tst:27672"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.18255" test_ref="oval:org.mitre.oval:tst:27453"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.22398" test_ref="oval:org.mitre.oval:tst:27494"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on XP x86/x64, Server 2003 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18928" test_ref="oval:org.mitre.oval:tst:27064"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on XP x86/x64, Server 2003 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.23019" test_ref="oval:org.mitre.oval:tst:27361"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18928" test_ref="oval:org.mitre.oval:tst:27064"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.23019" test_ref="oval:org.mitre.oval:tst:27361"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - GDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.16588" test_ref="oval:org.mitre.oval:tst:27609"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - LDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:10804"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.20708" test_ref="oval:org.mitre.oval:tst:27372"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:738" version="10" class="vulnerability">
      <metadata>
        <title>Redirect Cross-Domain Information Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference ref_id="CVE-2006-3280" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3280" source="CVE"/>
        <description>Cross-domain vulnerability in Microsoft Internet Explorer 6.0 allows remote attackers to access restricted information from other domains via an object tag with a data parameter that references a link on the attacker's originating site that specifies a Location HTTP header that references the target site, which then makes that content available through the outerHTML attribute of the object, aka "Redirect Cross-Domain Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:36.755-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:48.367-04:00">ACCEPTED</status_change>
            <modified comment="Added an anchor to the regex used to check for Internet Explorer 6." date="2007-01-11T20:38:00.950-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-01-11T20:49:18.371-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:55.268-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:2185 - Anchored regular expression" date="2011-02-22T12:51:00.261-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:52:33.760-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:18.093-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:49.566-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:26.309-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:136 - modified comments" date="2014-02-28T15:13:00.247-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-28T15:16:20.612-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:33.887-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:738 - Addressed validation errors and duplicate extended definitions" date="2015-07-13T20:21:00.869-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:25:23.406-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:02:05.904-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Server 2003-Gold">
          <extend_definition comment="Microsoft Windows Server 2003 (x86) Gold is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.554" test_ref="oval:org.mitre.oval:tst:136"/>
        </criteria>
        <criteria comment="XP,SP1 (64-bit) and Server 2003, SP1">
          <criteria operator="OR" comment="Windows XP (64-bit,SP1) or Server 2003 (SP1) is installed">
            <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2759" test_ref="oval:org.mitre.oval:tst:175"/>
        </criteria>
        <criteria comment="IE 6 on Windows XP,SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.2963" test_ref="oval:org.mitre.oval:tst:95"/>
        </criteria>
        <criteria comment="IE 6 on Windows 2000 or XP,SP1 (32-bit)">
          <criteria operator="OR" comment="Win2K,SP4 or XP,SP1 (32-bit) is installed">
            <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
            <extend_definition comment="Microsoft Windows XP SP1 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1561" test_ref="oval:org.mitre.oval:tst:56"/>
        </criteria>
        <criteria comment="IE 5.01,SP4 on Win2k,SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3842.3000" test_ref="oval:org.mitre.oval:tst:106"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7324" version="11" class="vulnerability">
      <metadata>
        <title>Uninitialized Memory Corruption Vulnerability (CVE-2010-1259)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1259" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1259"/>
        <description>Microsoft Internet Explorer 6 SP1 and SP2, 7, and 8 allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-06-14T11:32:12.647-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:44.204-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:40.868-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:10804 - Updated comments to test ID's tst:10804 &amp; tst:10787. And also corrected the version to state ID's ste:6638 &amp; ste:6932 by adding comments according to the MS Bulletins." date="2011-07-18T15:25:00.211-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-07-18T15:27:07.127-04:00">INTERIM</status_change>
            <status_change date="2011-08-08T04:00:56.029-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:46.790-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:46.790-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:54.956-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:25:11.667-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:21.878-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7324 - extended definitions of OS are without SP checks" date="2014-07-28T17:37:00.435-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:39:30.366-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:26.869-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 6 on Windows 2000 - RTMGDR">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1649" test_ref="oval:org.mitre.oval:tst:27761"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3698" test_ref="oval:org.mitre.oval:tst:27446"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5969" test_ref="oval:org.mitre.oval:tst:27626"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x64, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4696" test_ref="oval:org.mitre.oval:tst:27176"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on XP x86/x64 - GDR">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.17063" test_ref="oval:org.mitre.oval:tst:27760"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on XP x86/x64 - QFE">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21264" test_ref="oval:org.mitre.oval:tst:27363"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Server 2003 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.17063" test_ref="oval:org.mitre.oval:tst:27760"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Server 2003 x86/x64/ia64 - QFE">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21264" test_ref="oval:org.mitre.oval:tst:27363"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.18470" test_ref="oval:org.mitre.oval:tst:27673"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.22685" test_ref="oval:org.mitre.oval:tst:27672"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.18255" test_ref="oval:org.mitre.oval:tst:27453"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.22398" test_ref="oval:org.mitre.oval:tst:27494"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on XP x86/x64, Server 2003 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18928" test_ref="oval:org.mitre.oval:tst:27064"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on XP x86/x64, Server 2003 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.23019" test_ref="oval:org.mitre.oval:tst:27361"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18928" test_ref="oval:org.mitre.oval:tst:27064"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.23019" test_ref="oval:org.mitre.oval:tst:27361"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - GDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.16588" test_ref="oval:org.mitre.oval:tst:27609"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - LDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:10804"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.20708" test_ref="oval:org.mitre.oval:tst:27372"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7283" version="9" class="vulnerability">
      <metadata>
        <title>Win32k TrueType Font Parsing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1255" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1255"/>
        <description>The Windows kernel-mode drivers in win32k.sys in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 Gold and SP2, Windows 7, and Server 2008 R2 allows local users to execute arbitrary code via vectors related to "glyph outline information" and TrueType fonts, aka "Win32k TrueType Font Parsing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-06-14T11:31:25.000-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:36.500-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:37.735-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7283 - Modified GDR/LDR service branch format to read easier, removed duplicate, and updated extended def for Vista." date="2011-01-31T15:59:00.878-05:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-01-31T16:00:06.146-05:00">INTERIM</status_change>
            <status_change date="2011-02-21T04:01:13.412-05:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:00.744-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:00.744-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:50.446-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5160 - contains tests with modified comments and all dependences" date="2014-02-13T12:19:00.287-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:22:57.050-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:21.536-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of win32k.sys is less than 5.0.2195.7397" test_ref="oval:org.mitre.oval:tst:27601"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="the version of win32k.sys is less than 5.1.2600.3706" test_ref="oval:org.mitre.oval:tst:27275"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of win32k.sys is less than 5.1.2600.5976" test_ref="oval:org.mitre.oval:tst:27640"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of win32k.sys is less than 5.2.3790.4702" test_ref="oval:org.mitre.oval:tst:27693"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Vista x86/x64 SP1, all Server 2008 x86/x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of win32k.sys is less than 6.0.6001.18468" test_ref="oval:org.mitre.oval:tst:27353"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of win32k.sys is less than 6.0.6001.22682" test_ref="oval:org.mitre.oval:tst:27380"/>
              <criterion comment="the version of win32k.sys is greater than 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:10142"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Vista x86/x64 SP2, Server 2008 x86/64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of win32k.sys is less than 6.0.6002.18253" test_ref="oval:org.mitre.oval:tst:27138"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of win32k.sys is less than 6.0.6002.22396" test_ref="oval:org.mitre.oval:tst:27022"/>
              <criterion comment="the version of win32k.sys is greater than 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10124"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of win32k.sys is less than 6.1.7600.16585" test_ref="oval:org.mitre.oval:tst:27474"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of win32k.sys is greater than or equal to 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:27587"/>
              <criterion comment="the version of win32k.sys is less than 6.1.7600.20704" test_ref="oval:org.mitre.oval:tst:27593"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7281" version="3" class="vulnerability">
      <metadata>
        <title>Media Player Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Windows Media Player 9</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0268" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0268"/>
        <description>Unspecified vulnerability in the Windows Media Player ActiveX control in Windows Media Player (WMP) 9 on Microsoft Windows 2000 SP4 and XP SP2 and SP3 allows remote attackers to execute arbitrary code via crafted media content, aka "Media Player Remote Code Execution Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-13T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-04-15T10:43:15.995-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:48.703-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:34.527-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Windows Media Player 9 on Windows 2000, XP SP2">
          <extend_definition comment="Windows Media Player v9.0 is installed." definition_ref="oval:org.mitre.oval:def:2147"/>
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          </criteria>
          <criterion comment="the version of Wmp.dll is less than 9.0.0.3367" test_ref="oval:org.mitre.oval:tst:11473"/>
        </criteria>
        <criteria comment="Windows Media Player 9 on Windows XP SP3">
          <extend_definition comment="Windows Media Player v9.0 is installed." definition_ref="oval:org.mitre.oval:def:2147"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of Wmp.dll is less than 9.0.0.4508" test_ref="oval:org.mitre.oval:tst:11078"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7275" version="3" class="vulnerability" deprecated="true">
      <metadata>
        <title>HTML Sanitization Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Office SharePoint Server 2007</product>
          <product>Microsoft Windows SharePoint Services 3.0</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3243" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3243"/>
        <description>Cross-site scripting (XSS) vulnerability in the toStaticHTML function in Microsoft Internet Explorer 8, and the SafeHTML function in Microsoft Windows SharePoint Services 3.0 SP2 and Office SharePoint Server 2007 SP2, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "HTML Sanitization Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2010-10-18T21:48:30.253-04:00">DRAFT</status_change>
            <status_change date="2010-11-03T14:29:32.570-04:00">DEPRECATED</status_change>
            <modified comment="Updated inetlisteningservers_objects to match Schematron rules.  Set the local_port entities to be datatype, 'int'." date="2010-09-02T20:49:00.470-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:def:7275 - Multiple updates to several Windows OVAL entities. Includes CPE, title, and description updates. Fixed incorrectly referenced criteria. Added new criteria, fixed criteria checks, and improved criteria comments for several definitions." date="2012-11-02T20:20:00.882-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:12311 - MS13-084, 085 and 067 bulletins" date="2013-10-23T11:46:00.610-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Vulnerable Microsoft Office SharePoint Server 2007">
          <extend_definition comment="Microsoft Office SharePoint Server 2007 is installed." definition_ref="oval:org.mitre.oval:def:2313"/>
          <criterion comment="the version of Osafehtm.dll is less than 12.0.6545.5000" test_ref="oval:org.mitre.oval:tst:11537"/>
        </criteria>
        <criteria comment="Vulnerable Microsoft Windows SharePoint Services 3.0">
          <criteria operator="OR" comment="Windows Server 2003 32-bit or Windows Server 2003 64-bit">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <criterion comment="Microsoft Windows SharePoint Services 3.0 are installed" test_ref="oval:org.mitre.oval:tst:27622"/>
          <criterion comment="the version of Onetutil.dll is less than 12.0.6545.5002" test_ref="oval:org.mitre.oval:tst:11364"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:727" version="3" class="vulnerability">
      <metadata>
        <title>Korean IME Privilege Elevation Vulnerability in Office 2003 and Accessories</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0008" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0008"/>
        <description>The ShellAbout API call in Korean Input Method Editor (IME) in Korean versions of Microsoft Windows XP SP1 and SP2, Windows Server 2003 up to SP1, and Office 2003, allows local users to gain privileges by launching the "shell about dialog box" and clicking the "End-User License Agreement" link, which executes Notepad with the privileges of the program that displays the about box.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-17T07:36:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-22T08:27:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:727 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:06:23.126-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:46.180-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="the version of Imekr70.ime is less than 7.0.8002.0 (Office 2003 and Accessories)" test_ref="oval:org.mitre.oval:tst:2389"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:723" version="4" class="vulnerability">
      <metadata>
        <title>DNS Client Buffer Overrun Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference ref_id="CVE-2006-3441" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3441" source="CVE"/>
        <description>Buffer overflow in the DNS Client service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted record response.  NOTE: while MS06-041 implies that there is a single issue, there are multiple vectors, and likely multiple vulnerabilities, related to (1) a heap-based buffer overflow in a DNS server response to the client, (2) a DNS server response with malformed ATMA records, and (3) a length miscalculation in TXT, HINFO, X25, and ISDN records.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:36.303-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:47.770-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:723 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:05:42.254-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:43.757-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win2K,SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="The version of dnsapi.dll is less than 5.0.2195.7100." test_ref="oval:org.mitre.oval:tst:130"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP1">
          <extend_definition comment="Microsoft Windows XP SP1 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          <criterion comment="The version of dnsapi.dll is less than 5.1.2600.1863." test_ref="oval:org.mitre.oval:tst:81"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="The version of dnsapi.dll is less than 5.1.2600.2938." test_ref="oval:org.mitre.oval:tst:198"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP1 (64-bit)">
          <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="The version of dnsapi.dll is less than 5.2.3790.2745." test_ref="oval:org.mitre.oval:tst:51"/>
        </criteria>
        <criteria operator="AND" comment="S03-Gold">
          <extend_definition comment="Microsoft Windows Server 2003 (x86) Gold is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="The version of dnsapi.dll is less than 5.2.3790.558." test_ref="oval:org.mitre.oval:tst:159"/>
        </criteria>
        <criteria operator="AND" comment="S03,SP1">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="The version of dnsapi.dll is less than 5.2.3790.2745." test_ref="oval:org.mitre.oval:tst:51"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:722" version="7" class="vulnerability">
      <metadata>
        <title>Win2K/XP,SP1 IE Mismatched Document Object Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1790" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1790"/>
        <description>Microsoft Internet Explorer 6 SP2 6.0.2900.2180 and 6.0.2800.1106, and earlier versions, allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a Javascript BODY onload event that calls the window function, aka "Mismatched Document Object Model Objects Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-11T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-12T10:00:00.000-04:00">DRAFT</status_change>
            <modified date="2005-12-14T12:00:00.000-04:00" comment="Updated with newly available information.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:45:57.849-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:54.977-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:44:36.662-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:03:24.948-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:46.982-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:26.143-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Win2K or XP,SP1 is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2800.1528" negate="false" test_ref="oval:org.mitre.oval:tst:2390"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7194" version="5" class="vulnerability">
      <metadata>
        <title>IE v6.0,SP1 Plug-in Navigation Address Bar Spoofing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0843" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0843"/>
        <description>Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the "Plug-in Navigation Address Bar Spoofing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-25T07:44:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-27T01:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-17T10:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-27T10:50:00.000-04:00" comment="modified wft-564 - Changed test to match comment">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:45:58.632-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:54.717-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:36.130-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:26.063-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1476" negate="false" test_ref="oval:org.mitre.oval:tst:856"/>
          <criterion comment="the patch kb834707 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:855"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:719" version="10" class="vulnerability">
      <metadata>
        <title>COM Object Instantiation Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference ref_id="CVE-2006-3638" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3638" source="CVE"/>
        <description>Microsoft Internet Explorer 5.01 and 6 does not properly handle uninitialized COM objects, which allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code, as demonstrated by the Nth function in the DirectAnimation.DATuple ActiveX control, aka "COM Object Instantiation Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:35.956-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:47.310-04:00">ACCEPTED</status_change>
            <modified comment="Added an anchor to the regex used to check for Internet Explorer 6." date="2007-01-11T20:38:00.950-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-01-11T20:49:14.996-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:54.389-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:2185 - Anchored regular expression" date="2011-02-22T12:51:00.261-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:52:34.216-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:01:10.557-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:29:00.119-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:25.961-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:136 - modified comments" date="2014-02-28T15:13:00.247-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-28T15:16:20.895-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:32.582-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:719 - Addressed validation errors and duplicate extended definitions" date="2015-07-13T20:21:00.869-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:25:21.541-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:02:03.491-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Server 2003-Gold">
          <extend_definition comment="Microsoft Windows Server 2003 (x86) Gold is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.554" test_ref="oval:org.mitre.oval:tst:136"/>
        </criteria>
        <criteria comment="XP,SP1 (64-bit) and Server 2003, SP1">
          <criteria operator="OR" comment="Windows XP (64-bit,SP1) or Server 2003 (SP1) is installed">
            <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2759" test_ref="oval:org.mitre.oval:tst:175"/>
        </criteria>
        <criteria comment="IE 6 on Windows XP,SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.2963" test_ref="oval:org.mitre.oval:tst:95"/>
        </criteria>
        <criteria comment="IE 6 on Windows 2000 or XP,SP1 (32-bit)">
          <criteria operator="OR" comment="Win2K,SP4 or XP,SP1 (32-bit) is installed">
            <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
            <extend_definition comment="Microsoft Windows XP SP1 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1561" test_ref="oval:org.mitre.oval:tst:56"/>
        </criteria>
        <criteria comment="IE 5.01,SP4 on Win2k,SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3842.3000" test_ref="oval:org.mitre.oval:tst:106"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7158" version="11" class="vulnerability">
      <metadata>
        <title>XML Signature HMAC Truncation Authentication Bypass Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft .NET Framework</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0217" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0217"/>
        <description>The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in products including (1) the Oracle Security Developer Tools component in Oracle Application Server 10.1.2.3, 10.1.3.4, and 10.1.4.3IM; (2) the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, and 8.1 SP6; (3) Mono before 2.4.2.2; (4) XML Security Library before 1.2.12; (5) IBM WebSphere Application Server Versions 6.0 through 6.0.2.33, 6.1 through 6.1.0.23, and 7.0 through 7.0.0.1; (6) Sun JDK and JRE Update 14 and earlier; (7) Microsoft .NET Framework 3.0 through 3.0 SP2, 3.5, and 4.0; and other products uses a parameter that defines an HMAC truncation length (HMACOutputLength) but does not require a minimum for this length, which allows attackers to spoof HMAC-based signatures and bypass authentication by specifying a truncation length with a small number of bits.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-06-14T11:33:22.713-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:28.102-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:29.682-04:00">ACCEPTED</status_change>
            <modified comment="Removed the Windows Server 2003 SP2 (x86) extended def reference in the larger .Net Framework 1.1 criteria section.  The proper test for .Net Framework 1.1 on 2003 x86 was already broken out separately." date="2010-07-28T13:32:00.593-04:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2010-07-28T13:33:31.800-04:00">INTERIM</status_change>
            <status_change date="2010-08-16T04:10:49.309-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:57.243-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:57.243-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:46.216-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7158 - Submitting updated MS10-041 bulletin. def:7158 - updated to include LDR support." date="2013-05-29T15:56:00.291-04:00">
              <contributor organization="SecPod Technologies">Sharath S</contributor>
            </modified>
            <status_change date="2013-05-29T15:59:21.130-04:00">INTERIM</status_change>
            <status_change date="2013-06-17T04:00:30.601-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7158 - extended definitions of OS are without SP checks" date="2014-07-28T17:44:00.322-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:46:27.851-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:24.788-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment=".NET Framework 1.1 SP1">
          <criteria operator="OR" comment="For OS Check">
            <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 1.1 Service Pack 1 is Installed" definition_ref="oval:org.mitre.oval:def:1834"/>
          <criterion comment="the version of Mscorlib.dll is less than 1.1.4322.2463" test_ref="oval:org.mitre.oval:tst:27588"/>
        </criteria>
        <criteria operator="AND" comment=".NET Framework 1.1 Service Pack 1">
          <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
          <extend_definition comment="Microsoft .NET Framework 1.1 Service Pack 1 is Installed" definition_ref="oval:org.mitre.oval:def:1834"/>
          <criterion comment="the version of System.Security.dll is less than 1.1.4322.2460" test_ref="oval:org.mitre.oval:tst:27732"/>
        </criteria>
        <criteria operator="AND" comment=".NET Framework 3.5">
          <criteria operator="OR" comment="For OS Check">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 Original Release is installed" definition_ref="oval:org.mitre.oval:def:6689"/>
          <criterion comment="System.web.dll version is less than 2.0.50727.1878" test_ref="oval:org.mitre.oval:tst:27523"/>
        </criteria>
        <criteria operator="AND" comment=".NET Framework 2.0 SP2 or 3.5 SP1">
          <criteria operator="OR" comment="For OS Check">
            <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for Microsoft .NET Framework 2.0 Service Pack 2 or 3.5 SP1">
            <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
            <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          </criteria>
          <criteria operator="OR" comment="Check for GDR and LDR versions">
            <criterion comment="the version of System.Security.dll is less than 2.0.50727.3613" test_ref="oval:org.mitre.oval:tst:27623"/>
            <criteria operator="AND" comment="Check for LDR version">
              <criterion comment="Check if System.Security.dll version is greater than or equal to 2.0.50727.4000" test_ref="oval:org.mitre.oval:tst:81021"/>
              <criterion comment="Check if System.Security.dll version is less than 2.0.50727.4434" test_ref="oval:org.mitre.oval:tst:81257"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET Framework 3.5">
          <criteria operator="OR" comment="For OS Check">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 Original Release is installed" definition_ref="oval:org.mitre.oval:def:6689"/>
          <criterion comment="the version of System.Security.dll is less than 2.0.50727.1879" test_ref="oval:org.mitre.oval:tst:27098"/>
        </criteria>
        <criteria operator="AND" comment=".NET Framework 3.5 SP1 on Vista x86/x64, Windows Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="For OS Check">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="Check for GDR and LDR versions">
            <criterion comment="the version of system.security.dll is less than 2.0.50727.4204" test_ref="oval:org.mitre.oval:tst:27451"/>
            <criteria operator="AND" comment="Check for LDR versions">
              <criterion comment="Check if System.Security.dll version is greater than or equal to 2.0.50727.4300" test_ref="oval:org.mitre.oval:tst:80770"/>
              <criterion comment="Check if System.Security.dll version is less than 2.0.50727.4434" test_ref="oval:org.mitre.oval:tst:81257"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Microsoft .NET Framework 3.5.1 on Windows 7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="For OS Check">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="Check for GDR and LDR versions">
            <criterion comment="the version of system.security.dll is less than 2.0.50727.4951" test_ref="oval:org.mitre.oval:tst:27053"/>
            <criteria operator="AND" comment="Check for LDR versions">
              <criterion comment="Check if System.Security.dll version is greater than or equal to 2.0.50727.5000" test_ref="oval:org.mitre.oval:tst:80869"/>
              <criterion comment="Check if system.security.dll version is less than 2.0.50727.5007" test_ref="oval:org.mitre.oval:tst:81083"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7145" version="11" class="vulnerability">
      <metadata>
        <title>Cross-Domain Information Disclosure Vulnerability (CVE-2010-0255)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0255" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0255"/>
        <description>Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not prevent rendering of non-HTML local files as HTML documents, which allows remote attackers to bypass intended access restrictions and read arbitrary files via vectors involving JavaScript exploit code that constructs a reference to a file://127.0.0.1 URL, aka the dynamic OBJECT tag vulnerability, as demonstrated by obtaining the data from an index.dat file, a variant of CVE-2009-1140 and related to CVE-2008-1448.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-06-14T11:32:13.531-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:25.186-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:27.675-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:10804 - Updated comments to test ID's tst:10804 &amp; tst:10787. And also corrected the version to state ID's ste:6638 &amp; ste:6932 by adding comments according to the MS Bulletins." date="2011-07-18T15:25:00.211-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-07-18T15:27:10.846-04:00">INTERIM</status_change>
            <status_change date="2011-08-08T04:00:54.507-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:59.540-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:59.540-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:44.427-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:25:08.193-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:20.857-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7145 - extended definitions of OS are without SP checks" date="2014-07-28T17:36:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:37:54.331-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:24.431-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 7 on XP x86/x64 - GDR">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.17063" test_ref="oval:org.mitre.oval:tst:27760"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on XP x86/x64 - QFE">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21264" test_ref="oval:org.mitre.oval:tst:27363"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Server 2003 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.17063" test_ref="oval:org.mitre.oval:tst:27760"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Server 2003 x86/x64/ia64 - QFE">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21264" test_ref="oval:org.mitre.oval:tst:27363"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.18470" test_ref="oval:org.mitre.oval:tst:27673"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.22685" test_ref="oval:org.mitre.oval:tst:27672"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.18255" test_ref="oval:org.mitre.oval:tst:27453"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64, Server 2008 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.22398" test_ref="oval:org.mitre.oval:tst:27494"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on XP x86/x64, Server 2003 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18928" test_ref="oval:org.mitre.oval:tst:27064"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on XP x86/x64, Server 2003 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.23019" test_ref="oval:org.mitre.oval:tst:27361"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, all Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18928" test_ref="oval:org.mitre.oval:tst:27064"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, all Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.23019" test_ref="oval:org.mitre.oval:tst:27361"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - GDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.16588" test_ref="oval:org.mitre.oval:tst:27609"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - LDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:10804"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.20708" test_ref="oval:org.mitre.oval:tst:27372"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:714" version="6" class="vulnerability">
      <metadata>
        <title>Win2k Embedded Web Font Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0010" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0010"/>
        <description>Heap-based buffer overflow in T2EMBED.DLL in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1, Windows 98, and Windows ME allows remote attackers to execute arbitrary code via an e-mail message or web page with a crafted Embedded Open Type (EOT) web font that triggers the overflow during decompression.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-11T12:56:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-12T09:18:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-01T09:08:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed regex in ste:2889.  Implemented by Matthew Wojcik." date="2007-03-06T18:19:00.507-05:00">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2007-03-06T18:21:11.052-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:24.629-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:714 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:05:22.084-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:03:23.639-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criteria operator="OR" comment="Fontsub.dll &lt; 5.0.2195.7071 or T2embed.dll &lt;5.0.2195.7073 (Win2k,SP4)">
          <criterion comment="the version of Fontsub.dll is less than 5.0.2195.7071" test_ref="oval:org.mitre.oval:tst:2397"/>
          <criterion comment="the version of T2embed.dll is less than 5.0.2195.7073" test_ref="oval:org.mitre.oval:tst:2396"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7130" version="3" class="vulnerability">
      <metadata>
        <title>Windows Kernel Symbolic Link Creation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0237" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0237"/>
        <description>The kernel in Microsoft Windows 2000 SP4 and XP SP2 and SP3 allows local users to gain privileges by creating a symbolic link from an untrusted registry hive to a trusted registry hive, aka "Windows Kernel Symbolic Link Creation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-13T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-04-15T10:42:27.480-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:43.928-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:30.091-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4 or later">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 5.0.2195.7376" test_ref="oval:org.mitre.oval:tst:11458"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 5.1.2600.3670" test_ref="oval:org.mitre.oval:tst:11347"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 5.1.2600.5938" test_ref="oval:org.mitre.oval:tst:11896"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:713" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 Hyperlink Object Library Unchecked Buffer Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Hyperlink Object Library</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0057" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0057"/>
        <description>The Hyperlink Object Library for Windows 98, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a crafted link that triggers an "unchecked buffer" in the library, possibly due to a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-02-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-02-11T09:34:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-03-02T09:01:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-23T08:09:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="the version of hlink.dll is less than 5.2.3790.227" negate="false" test_ref="oval:org.mitre.oval:tst:2399"/>
        <criterion comment="the patch kb888113 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2398"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7129" version="8" class="vulnerability">
      <metadata>
        <title>SMB Client Memory Allocation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0269" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0269"/>
        <description>The SMB client in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly allocate memory for SMB responses, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code via a crafted (1) SMBv1 or (2) SMBv2 response, aka "SMB Client Memory Allocation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-13T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-04-15T10:42:12.648-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:43.173-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:29.207-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:44.806-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:44.806-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:43.510-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4525 - contains tests with modified comments and all dependences" date="2014-02-13T12:19:00.287-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:23:15.061-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4401 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-03T04:01:20.523-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4 or later">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Mrxsmb.sys version is less than 5.0.2195.7379" test_ref="oval:org.mitre.oval:tst:11414"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="Mrxsmb.sys version is less than 5.1.2600.3675" test_ref="oval:org.mitre.oval:tst:11126"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Mrxsmb.sys version is less than 5.1.2600.5944" test_ref="oval:org.mitre.oval:tst:11710"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="Mrxsmb.sys version is less than 5.2.3790.4671" test_ref="oval:org.mitre.oval:tst:11515"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9035"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.0.6000.17025" test_ref="oval:org.mitre.oval:tst:11088"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9423"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.0.6000.21230" test_ref="oval:org.mitre.oval:tst:11469"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9505"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.0.6001.18431" test_ref="oval:org.mitre.oval:tst:11662"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9535"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.0.6001.22641" test_ref="oval:org.mitre.oval:tst:11205"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.0.6002.18000" test_ref="oval:org.mitre.oval:tst:20899"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.0.6002.18213" test_ref="oval:org.mitre.oval:tst:10963"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:20464"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.0.6002.22346" test_ref="oval:org.mitre.oval:tst:11499"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.1.7600.16000" test_ref="oval:org.mitre.oval:tst:20680"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.1.7600.16539" test_ref="oval:org.mitre.oval:tst:11279"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="Mrxsmb10.sys version is greater than or equal 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:20484"/>
          <criterion comment="Mrxsmb10.sys version is less than 6.1.7600.20655" test_ref="oval:org.mitre.oval:tst:11856"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7124" version="9" class="vulnerability">
      <metadata>
        <title>Uninitialized Memory Corruption Vulnerability (CVE-2010-1261)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1261" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1261"/>
        <description>The IE8 Developer Toolbar in Microsoft Internet Explorer 8 SP1, SP2, and SP3 allows user-assisted remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-06-14T11:32:18.985-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:23.322-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:26.457-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:10804 - Updated comments to test ID's tst:10804 &amp; tst:10787. And also corrected the version to state ID's ste:6638 &amp; ste:6932 by adding comments according to the MS Bulletins." date="2011-07-18T15:25:00.211-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-07-18T15:27:12.401-04:00">INTERIM</status_change>
            <status_change date="2011-08-08T04:00:53.783-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:45.525-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:45.525-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:41.688-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7124 - extended definitions of OS are without SP checks" date="2014-07-28T17:36:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:37:55.328-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:23.490-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 8 on XP x86/x64, Server 2003 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18928" test_ref="oval:org.mitre.oval:tst:27064"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on XP x86/x64, Server 2003 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.23019" test_ref="oval:org.mitre.oval:tst:27361"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, all Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18928" test_ref="oval:org.mitre.oval:tst:27064"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, all Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.23019" test_ref="oval:org.mitre.oval:tst:27361"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - GDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.16588" test_ref="oval:org.mitre.oval:tst:27609"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - LDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:10804"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.20708" test_ref="oval:org.mitre.oval:tst:27372"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7113" version="3" class="vulnerability">
      <metadata>
        <title>Windows Kernel Memory Allocation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0236" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0236"/>
        <description>The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Vista Gold does not properly allocate memory for the destination key associated with a symbolic-link registry key, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Allocation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-13T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-04-15T10:42:27.105-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:42.661-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:28.461-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4 or later">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 5.0.2195.7376" test_ref="oval:org.mitre.oval:tst:11458"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 5.1.2600.3670" test_ref="oval:org.mitre.oval:tst:11347"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 5.1.2600.5938" test_ref="oval:org.mitre.oval:tst:11896"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is less than 5.2.3790.4666" test_ref="oval:org.mitre.oval:tst:11857"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Server 2003 ia64 SP2">
          <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          <criterion comment="The version of Ntkrnlmp.exe is less than 5.2.3790.4666" test_ref="oval:org.mitre.oval:tst:11611"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6000.16000" test_ref="oval:org.mitre.oval:tst:10882"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6000.17021" test_ref="oval:org.mitre.oval:tst:11259"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:10762"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6000.21226" test_ref="oval:org.mitre.oval:tst:11841"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:71" version="2" class="vulnerability">
      <metadata>
        <title>Privilege Escalation Using Cached Admin Connection</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft SQL Server 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0344" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0344"/>
        <description>An SQL query method in Microsoft SQL Server 2000 Gold and 7.0 using Mixed Mode allows local database users to gain privileges by reusing a cached connection of the sa administrator account.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-06-24T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-04-07T12:00:00.000-04:00" comment="modified wft-222 - corrected literal component of file path. It was missing the leading '\'">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified date="2005-04-07T09:25:00.000-04:00" comment="modified wft-222 - Corrected comment">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2005-04-11T08:48:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="SQL Server 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2977"/>
          <criterion comment="the version of sqlservr.exe is less than 2000.80.296.0" negate="false" test_ref="oval:org.mitre.oval:tst:2976"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Mixed Mode Enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2975"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7095" version="4" class="vulnerability">
      <metadata>
        <title>IE v5.5,SP2 Plug-in Navigation Address Bar Spoofing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0843" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0843"/>
        <description>Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the "Plug-in Navigation Address Bar Spoofing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-25T05:31:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-27T01:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-17T10:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:42:00.000-04:00" comment="modified wft-562 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:43.509-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:25.812-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
        <criterion comment="the version of mshtml.dll is less than 5.50.4945.2800" negate="false" test_ref="oval:org.mitre.oval:tst:384"/>
        <criterion comment="the patch kb834707 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:855"/>
        <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
          <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
            <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
            <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
            <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
          </criteria>
          <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
            <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
            <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
            <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7084" version="4" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP3 Similar Method Name Redirection Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0727" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0727"/>
        <description>Microsoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows remote web servers to bypass zone restrictions and execute arbitrary code in the local computer zone by redirecting a function to another function with the same name, as demonstrated by SimilarMethodNameRedir, aka the "Similar Method Name Redirection Cross Domain Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-19T07:22:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-20T02:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2824. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:48:00.494-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:52:28.926-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:53.871-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:41.869-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:25.745-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3015"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3821.2800" negate="false" test_ref="oval:org.mitre.oval:tst:625"/>
          <criterion comment="the patch kb834707-ie501sp3 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:624"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7072" version="5" class="vulnerability">
      <metadata>
        <title>OpenType CFF Font Driver Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0819" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0819"/>
        <description>Unspecified vulnerability in the Windows OpenType Compact Font Format (CFF) driver in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users to execute arbitrary code via unknown vectors related to improper validation when copying data from user mode to kernel mode, aka "OpenType CFF Font Driver Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-06-14T11:32:45.172-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:19.758-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:24.036-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:01.165-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:01.165-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:40.093-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4 or later">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Atmfd.dll is less than 5.0.2.227" test_ref="oval:org.mitre.oval:tst:27043"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2/SP3">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          </criteria>
          <criterion comment="the version of Atmfd.dll is less than 5.1.2.228" test_ref="oval:org.mitre.oval:tst:27498"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of Atmfd.dll is less than 5.2.2.228" test_ref="oval:org.mitre.oval:tst:26783"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of Atmfd.dll is less than 5.1.2.228" test_ref="oval:org.mitre.oval:tst:27498"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="the version of Atmfd.dll is less than 5.1.2.228" test_ref="oval:org.mitre.oval:tst:27498"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="the version of Atmfd.dll is less than 5.1.2.228" test_ref="oval:org.mitre.oval:tst:27498"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7067" version="11" class="vulnerability">
      <metadata>
        <title>SMTP Server MX Record Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>SMTP</product>
          <product>Microsoft Exchange Server 2003</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0024" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0024"/>
        <description>The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Server 2008 Gold, SP2, and R2, and Exchange Server 2003 SP2, does not properly parse MX records, which allows remote DNS servers to cause a denial of service (service outage) via a crafted response to a DNS MX record query, aka "SMTP Server MX Record Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-13T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-04-15T10:42:57.808-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:40.554-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:26.034-04:00">ACCEPTED</status_change>
            <modified comment="Updated definition and related items because Microsoft has re-released the bulletin MS10-024 to reoffer the updates for Windows Server 2008 and Windows Server 2008 R2." date="2010-11-10T17:30:00.607-05:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2010-11-10T18:08:07.712-05:00">INTERIM</status_change>
            <status_change date="2010-11-29T04:00:20.982-05:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:02.087-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:02.087-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:39.330-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:24:59.067-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:20.280-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7067 - extended definitions of OS are without SP checks" date="2014-07-28T17:36:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:37:57.894-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:23.290-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <criterion comment="The version of smtpsvc.dll is less than 5.0.2195.7381" test_ref="oval:org.mitre.oval:tst:11642"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86)">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="The version of smtpsvc.dll is less than 6.0.2600.3680" test_ref="oval:org.mitre.oval:tst:11743"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86)">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="The version of smtpsvc.dll is less than 6.0.2600.5949" test_ref="oval:org.mitre.oval:tst:11572"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <criterion comment="The version of smtpsvc.dll is less than 6.0.3790.4675" test_ref="oval:org.mitre.oval:tst:11143"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Server 2008 32bit/x64">
          <criteria operator="OR" comment="Microsoft Server 2008 32bit/x64">
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="The version of smtpsvc.dll is less than 7.0.6001.18485" test_ref="oval:org.mitre.oval:tst:11603"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="The version of smtpsvc.dll is greater than or equal 7.0.6001.22000" test_ref="oval:org.mitre.oval:tst:11323"/>
              <criterion comment="The version of smtpsvc.dll is less than 7.0.6001.22704" test_ref="oval:org.mitre.oval:tst:11171"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Server 2008 32bit/x64">
          <criteria operator="OR" comment="Microsoft Server 2008 32bit/x64">
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="The version of smtpsvc.dll is less than 7.0.6002.18264" test_ref="oval:org.mitre.oval:tst:11520"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="The version of smtpsvc.dll is greater than or equal 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:11373"/>
              <criterion comment="The version of smtpsvc.dll is less than 7.0.6002.22417" test_ref="oval:org.mitre.oval:tst:11328"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Server 2008 R2 x86/x64/ia64">
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="The version of smtpsvc.dll is less than 7.5.7600.16601" test_ref="oval:org.mitre.oval:tst:11754"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="The version of smtpsvc.dll is greater than or equal 7.5.7600.20000" test_ref="oval:org.mitre.oval:tst:11889"/>
              <criterion comment="The version of smtpsvc.dll is less than 7.5.7600.20723" test_ref="oval:org.mitre.oval:tst:11532"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Exchange Server 2003 SP2">
          <extend_definition comment="Microsoft Exchange Server 2003 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:1869"/>
          <criterion comment="The version of Msgfilter.dll is less than 6.5.7656.2" test_ref="oval:org.mitre.oval:tst:11056"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:704" version="2" class="vulnerability">
      <metadata>
        <title>Windows 2000 WINS Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows Internet Naming Service (WINS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0825" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0825"/>
        <description>The Windows Internet Naming Service (WINS) for Microsoft Windows Server 2003, and possibly Windows NT and Server 2000, does not properly validate the length of certain packets, which allows attackers to cause a denial of service and possibly execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-31T04:13:00.000-04:00" comment="Replaced reference to obj:1374 with reference to obj:1550 since it references Product\Options and not ProductOptions in the controlset registry key.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:54:00.642-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows 2000 Server is installed">
            <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
            <criteria operator="OR" comment="Windows NT server product option">
              <criterion comment="this is an NT Server (stand-alone)" negate="false" test_ref="oval:org.mitre.oval:tst:2408"/>
              <criterion comment="this is an NT Server (domain controller)" negate="false" test_ref="oval:org.mitre.oval:tst:3035"/>
            </criteria>
          </criteria>
          <criterion comment="the version of wins.exe is less than 5.0.2195.6870" negate="false" test_ref="oval:org.mitre.oval:tst:2407"/>
          <criterion comment="the patch kb830352 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2406"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the wins service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2405"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7001" version="5" class="vulnerability">
      <metadata>
        <title>Media Services Stack-based Buffer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0478" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0478"/>
        <description>Stack-based buffer overflow in nsum.exe in the Windows Media Unicast Service in Media Services for Microsoft Windows 2000 Server SP4 allows remote attackers to execute arbitrary code via crafted packets associated with transport information, aka "Media Services Stack-based Buffer Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-13T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-04-15T10:43:01.080-04:00">DRAFT</status_change>
            <modified comment="corrected file name from Nscm.exe to Nsum.exe for obj:6532" date="2010-04-16T14:46:00.908-04:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <modified comment="Updated to include the new version for nsum.exe" date="2010-04-28T14:22:00.346-04:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2010-05-17T04:00:36.767-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:21.758-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
        <extend_definition comment="Microsoft Media Services 4.1 is installed" definition_ref="oval:org.mitre.oval:def:5705"/>
        <criterion comment="Nsum.exe version is less than 4.1.0.3939" test_ref="oval:org.mitre.oval:tst:11647"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:697" version="5" class="vulnerability">
      <metadata>
        <title>IE6,SP1 Web Folder Behaviors Cross-Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1989" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1989"/>
        <description>Unknown vulnerability in Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to obtain information and possibly execute code when browsing from a web site to a web folder view using WebDAV, aka "Web Folder Behaviors Cross-Domain Vulnerability".</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-23T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-08-25T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed reference to patch kb896727 from criteria.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:46:07.513-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:53.538-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:38.454-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:25.658-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criteria operator="OR" comment="the version of mshtml.dll is less than 6.0.2800.1515 or 6.0.2800.1516">
            <criterion comment="the version of mshtml.dll is less than 6.0.2800.1515 (RTMGDR)" negate="false" test_ref="oval:org.mitre.oval:tst:2418"/>
            <criterion comment="the version of mshtml.dll is less than 6.0.2800.1516 (RTMQFE)" negate="false" test_ref="oval:org.mitre.oval:tst:2417"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6954" version="3" class="vulnerability">
      <metadata>
        <title>Buffer overflow vulnerability in MDAC Function</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Data Access Components 2.5</product>
          <product>Microsoft Data Access Components 2.6</product>
          <product>Microsoft Data Access Components 2.7</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0353" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0353"/>
        <description>Buffer overflow in a component of SQL-DMO for Microsoft Data Access Components (MDAC) 2.5 through 2.7 allows remote attackers to execute arbitrary code via a long response to a broadcast request to UDP port 1434.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-30T14:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2010-05-05T15:40:49.796-04:00">DRAFT</status_change>
            <status_change date="2010-05-24T04:00:03.306-04:00">INTERIM</status_change>
            <status_change date="2010-06-14T04:00:27.316-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Microsoft Data Access Components 2.5 on Microsoft Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <criterion comment="Microsoft Data Access Components 2.5 is installed" test_ref="oval:org.mitre.oval:tst:2576"/>
          <criterion comment="File %windir%\System32\odbcbcp.dll is less than 3.70.11.40" test_ref="oval:org.mitre.oval:tst:1396"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Data Access Components 2.6 on Microsoft Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <criterion comment="Microsoft Data Access Components 2.6 is installed" test_ref="oval:org.mitre.oval:tst:1394"/>
          <criterion comment="File %windir%\System32\odbcbcp.dll is less than 2000.80.746.0" test_ref="oval:org.mitre.oval:tst:1393"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Data Access Components 2.7 on Microsoft Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <criterion comment="Microsoft Data Access Components 2.7 is installed" test_ref="oval:org.mitre.oval:tst:1258"/>
          <criterion comment="File %windir%\System32\odbcbcp.dll is less than 2000.81.9041.40" test_ref="oval:org.mitre.oval:tst:1259"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Data Access Components 2.7 on Microsoft Windows XP">
          <extend_definition comment="Microsoft Windows XP is installed" definition_ref="oval:org.mitre.oval:def:105"/>
          <criterion comment="Microsoft Data Access Components 2.7 is installed" test_ref="oval:org.mitre.oval:tst:1258"/>
          <criterion comment="File %windir%\System32\odbcbcp.dll is less than 2000.81.9041.40" test_ref="oval:org.mitre.oval:tst:1259"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6948" version="9" class="vulnerability">
      <metadata>
        <title>Win32k Window Creation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0485" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0485"/>
        <description>The Windows kernel-mode drivers in win32k.sys in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 Gold and SP2, Windows 7, and Server 2008 R2 "do not properly validate all callback parameters when creating a new window," which allows local users to execute arbitrary code, aka "Win32k Window Creation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-06-14T11:31:24.406-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:49:11.734-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:19.201-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6948 - Modified GDR/LDR service branch format to read easier, removed duplicate, and updated extended def for Vista." date="2011-01-31T15:59:00.878-05:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-01-31T16:00:04.782-05:00">INTERIM</status_change>
            <status_change date="2011-02-21T04:01:12.131-05:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:04.994-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:04.994-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:36.755-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5160 - contains tests with modified comments and all dependences" date="2014-02-13T12:19:00.287-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:23:00.911-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:19.764-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of win32k.sys is less than 5.0.2195.7397" test_ref="oval:org.mitre.oval:tst:27601"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="the version of win32k.sys is less than 5.1.2600.3706" test_ref="oval:org.mitre.oval:tst:27275"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of win32k.sys is less than 5.1.2600.5976" test_ref="oval:org.mitre.oval:tst:27640"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of win32k.sys is less than 5.2.3790.4702" test_ref="oval:org.mitre.oval:tst:27693"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Vista x86/x64 SP1, all Server 2008 x86/x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of win32k.sys is less than 6.0.6001.18468" test_ref="oval:org.mitre.oval:tst:27353"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of win32k.sys is less than 6.0.6001.22682" test_ref="oval:org.mitre.oval:tst:27380"/>
              <criterion comment="the version of win32k.sys is greater than 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:10142"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Vista x86/x64 SP2, Server 2008 x86/64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of win32k.sys is less than 6.0.6002.18253" test_ref="oval:org.mitre.oval:tst:27138"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of win32k.sys is less than 6.0.6002.22396" test_ref="oval:org.mitre.oval:tst:27022"/>
              <criterion comment="the version of win32k.sys is greater than 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10124"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of win32k.sys is less than 6.1.7600.16585" test_ref="oval:org.mitre.oval:tst:27474"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of win32k.sys is greater than or equal to 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:27587"/>
              <criterion comment="the version of win32k.sys is less than 6.1.7600.20704" test_ref="oval:org.mitre.oval:tst:27593"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:694" version="4" class="vulnerability">
      <metadata>
        <title>Visual Basic for Applications Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Visual Basic 6.0</product>
        </affected>
        <reference ref_id="CVE-2006-3649" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3649" source="CVE"/>
        <description>Buffer overflow in Microsoft Visual Basic for Applications (VBA) SDK 6.0 through 6.4, as used by Microsoft Office 2000 SP3, Office XP SP3, Project 2000 SR1, Project 2002 SP1, Access 2000 Runtime SP3, Visio 2002 SP2, and Works Suite 2004 through 2006, allows user-assisted attackers to execute arbitrary code via unspecified document properties that are not verified when VBA is invoked to open documents.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:35.094-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:46.846-04:00">ACCEPTED</status_change>
            <modified comment="References registry value for Common Files directory due to multilingual support" date="2008-04-14T11:07:00.744-04:00">
              <contributor organization="GFI Software">Clifford Farrugia</contributor>
            </modified>
            <status_change date="2008-04-14T12:25:45.747-04:00">INTERIM</status_change>
            <status_change date="2008-05-05T04:00:26.766-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:694 - Modified vulnerabilities - a lot of fixes" date="2015-07-22T13:29:00.390-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-22T13:32:17.953-04:00">INTERIM</status_change>
            <status_change date="2015-08-10T04:01:08.526-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Visual Basic 6.0 is installed" definition_ref="oval:org.mitre.oval:def:15369"/>
        <criterion comment="The version of vbe6.dll is less than 6.4.99.72." test_ref="oval:org.mitre.oval:tst:94"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:690" version="3" class="vulnerability">
      <metadata>
        <title>IE v5.5 Temporary Internet Files folders Name Reading Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1188" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1188"/>
        <description>Internet Explorer 5.01 through 6.0 allows remote attackers to identify the path to the Temporary Internet Files folder and obtain user information such as cookies via certain uses of the OBJECT tag, which are not subjected to the proper security checks, aka "Temporary Internet Files folders Name Reading."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-27T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:38.821-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:25.602-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Internet Explorer 5.5 Installed">
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3078"/>
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3077"/>
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3076"/>
          <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
        </criteria>
        <criterion comment="the version of mshtml.dll is less than 5.50.4922.900" negate="false" test_ref="oval:org.mitre.oval:tst:2786"/>
        <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
        <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
        <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:689" version="3" class="vulnerability">
      <metadata>
        <title>IE v5.5,SP2 Travel Log Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1026" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1026"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:37.129-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:25.546-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
          <criterion comment="the version of mshtml.dll is less than 5.50.4937.800" negate="false" test_ref="oval:org.mitre.oval:tst:2581"/>
          <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6886" version="10" class="vulnerability">
      <metadata>
        <title>Cabview Corruption Validation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Cabinet File Viewer Shell Extension</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0487" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0487"/>
        <description>The Authenticode Signature verification functionality in cabview.dll in Cabinet File Viewer Shell Extension 5.1, 6.0, and 6.1 in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly use unspecified fields in a file digest, which allows remote attackers to execute arbitrary code via a modified cabinet (aka .CAB) file that incorrectly appears to have a valid signature, aka "Cabview Corruption Validation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-13T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-04-15T10:41:58.556-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:30.840-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:15.984-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:08.744-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:08.744-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:33.662-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4525 - contains tests with modified comments and all dependences" date="2014-02-13T12:19:00.287-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:23:13.752-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:18.740-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6886 - extended definitions of OS are without SP checks" date="2014-07-28T17:49:00.293-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:51:13.740-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:21.439-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <criterion comment="the version of Cabview.dll is less than 5.0.3900.7369" test_ref="oval:org.mitre.oval:tst:11298"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86)">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="the version of Cabview.dll is less than 6.0.2900.3663" test_ref="oval:org.mitre.oval:tst:11381"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86)">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="the version of Cabview.dll is less than 6.0.2900.5927" test_ref="oval:org.mitre.oval:tst:11525"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <criterion comment="the version of Cabview.dll is less than 6.0.3790.4649" test_ref="oval:org.mitre.oval:tst:11740"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="the version of Cabview.dll is less than 6.0.6000.17002" test_ref="oval:org.mitre.oval:tst:11864"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="the version of Cabview.dll is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:11560"/>
          <criterion comment="the version of Cabview.dll is less than 6.0.6000.21203" test_ref="oval:org.mitre.oval:tst:11830"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64, Server 2008 32bit/x64/ia64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of Cabview.dll is less than 6.0.6001.18404" test_ref="oval:org.mitre.oval:tst:11297"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64, Server 2008 32bit/x64/ia64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of Cabview.dll is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:11529"/>
          <criterion comment="the version of Cabview.dll is less than 6.0.6001.22605" test_ref="oval:org.mitre.oval:tst:11130"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64, Server 2008 32bit/x64/ia64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 32bit/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of Cabview.dll is less than 6.0.6002.18184" test_ref="oval:org.mitre.oval:tst:11490"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64, Server 2008 32bit/x64/ia64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 32bit/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of Cabview.dll is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:11204"/>
          <criterion comment="the version of Cabview.dll is less than 6.0.6002.22311" test_ref="oval:org.mitre.oval:tst:11308"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="the version of Cabview.dll is less than 6.1.7600.16500" test_ref="oval:org.mitre.oval:tst:11424"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="the version of Cabview.dll is greater than or equal 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:11563"/>
          <criterion comment="the version of Cabview.dll is less than 6.1.7600.20613" test_ref="oval:org.mitre.oval:tst:11708"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:687" version="5" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP4 Travel Log Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1026" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1026"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:49:00.000-04:00" comment="modified wft-91 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed ste:2614: set datatype to version.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:54:00.319-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:59:42.977-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:53.220-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:37.271-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:25.473-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3813.800" negate="false" test_ref="oval:org.mitre.oval:tst:2582"/>
          <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6835" version="13" class="vulnerability">
      <metadata>
        <title>HTML Object Memory Corruption Vulnerability (CVE-2010-0249)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0249" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0249"/>
        <description>Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP2; Windows Server 2008 Gold, SP2, and R2; and Windows 7 allows remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object, related to incorrectly initialized memory and improper handling of objects in memory, as exploited in the wild in December 2009 and January 2010 during Operation Aurora, aka "HTML Object Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-15T14:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-01-19T07:03:25.323-05:00">DRAFT</status_change>
            <modified comment="Updated title, all tests and states" date="2010-01-22T11:57:00.675-05:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </modified>
            <modified comment="Updated to include tests for Windows XP SP2 (x86) running IE 7.  Microsoft bulletin MS10-002 (associated File Information article) did not include a reference to Windows XP SP2 (x86) running IE 7.0, though this is a vulnerable configuration and updated by the patch referenced in the article." date="2010-01-27T13:32:00.227-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2010-02-15T04:00:03.010-05:00">INTERIM</status_change>
            <status_change date="2010-03-08T04:00:07.692-05:00">ACCEPTED</status_change>
            <modified comment="Modified the mshtml.dll versions for IE8 on Windows 7 and Windows Server 2008 R2 in order to correctly identify the GDR and LDR branches." date="2010-05-11T13:38:00.735-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2010-05-11T13:41:03.899-04:00">INTERIM</status_change>
            <modified comment="Modified the mshtml.dll versions for IE8 on Windows 7 and Windows Server 2008 R2 in order to correctly identify the GDR and LDR branches." date="2010-05-11T13:41:00.299-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2010-05-31T04:00:30.203-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:6932 - Updated comments to test ID's tst:10804 &amp; tst:10787. And also corrected the version to state ID's ste:6638 &amp; ste:6932 by adding comments according to the MS Bulletins." date="2011-07-18T15:25:00.211-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-07-18T15:26:48.963-04:00">INTERIM</status_change>
            <status_change date="2011-08-08T04:00:51.963-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:51.540-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:51.540-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:30.779-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:25:01.102-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:18.374-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6835 - extended definitions of OS are without SP checks" date="2014-07-28T17:36:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:37:54.699-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:20.812-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE6/2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1644" test_ref="oval:org.mitre.oval:tst:11530"/>
        </criteria>
        <criteria operator="AND" comment="IE6/XP">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3660" test_ref="oval:org.mitre.oval:tst:11697"/>
        </criteria>
        <criteria operator="AND" comment="IE6/XP (32-bit)">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5921" test_ref="oval:org.mitre.oval:tst:11468"/>
        </criteria>
        <criteria operator="AND" comment="IE6/XP x64/server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4639" test_ref="oval:org.mitre.oval:tst:11646"/>
        </criteria>
        <criteria operator="AND" comment="IE7/XP x86/x64">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16981" test_ref="oval:org.mitre.oval:tst:11559"/>
        </criteria>
        <criteria operator="AND" comment="IE7/XP x86/x64">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21183" test_ref="oval:org.mitre.oval:tst:11207"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16981" test_ref="oval:org.mitre.oval:tst:11559"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21183" test_ref="oval:org.mitre.oval:tst:11207"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16982" test_ref="oval:org.mitre.oval:tst:20566"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21184" test_ref="oval:org.mitre.oval:tst:21091"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.16000" test_ref="oval:org.mitre.oval:tst:9444"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.18385" test_ref="oval:org.mitre.oval:tst:11423"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.22585" test_ref="oval:org.mitre.oval:tst:11500"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.18000" test_ref="oval:org.mitre.oval:tst:10094"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.18167" test_ref="oval:org.mitre.oval:tst:11846"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.22290" test_ref="oval:org.mitre.oval:tst:11562"/>
        </criteria>
        <criteria operator="AND" comment="IE8/XP x86/x64, Server 2003 x86/x64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18876" test_ref="oval:org.mitre.oval:tst:11452"/>
        </criteria>
        <criteria operator="AND" comment="IE8/XP x86/x64, Server 2003 x86/x64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22967" test_ref="oval:org.mitre.oval:tst:11309"/>
        </criteria>
        <criteria operator="AND" comment="IE8/Vista x86/x64, Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9771"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18882" test_ref="oval:org.mitre.oval:tst:11541"/>
        </criteria>
        <criteria operator="AND" comment="IE8/Vista x86/x64, Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.22973" test_ref="oval:org.mitre.oval:tst:11139"/>
        </criteria>
        <criteria operator="AND" comment="IE8/7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.16000" test_ref="oval:org.mitre.oval:tst:10787"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.16490" test_ref="oval:org.mitre.oval:tst:11780"/>
        </criteria>
        <criteria operator="AND" comment="IE8/7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:10804"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.20600" test_ref="oval:org.mitre.oval:tst:11312"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:682" version="7" class="vulnerability">
      <metadata>
        <title>Microsoft Agent Security Prompt Spoofing Vulnerability (Windows 2000)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Agent</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1214" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1214"/>
        <description>Microsoft Agent allows remote attackers to spoof trusted Internet content and execute arbitrary code by disguising security prompts on a malicious Web page.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-22T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-06-22T07:25:00.000-04:00">DRAFT</status_change>
            <modified date="2005-06-24T12:00:00.000-04:00" comment="added cve description">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-11-17T09:54:00.000-04:00" comment="Updated obj:1000 to use new variable var:759 for path reference rather than var:200.  Now uses 'msagent' subdir of SystemRoot instead of System32.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-11-17T09:54:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:54:00.438-05:00">ACCEPTED</status_change>
            <modified comment="Corrected and tightened regular expression in ste:2610" date="2010-12-02T11:46:00.307-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-12-02T11:47:27.247-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:01:09.056-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:43:56.813-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:03:20.482-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows 2000 (sp4 or earlier) is installed">
            <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
            <criterion comment="Win2K/XP/2003 service pack 5 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2790"/>
          </criteria>
          <criterion comment="the version of agentdpv.dll is less than 2.0.0.3423" negate="false" test_ref="oval:org.mitre.oval:tst:2425"/>
          <criterion comment="the patch kb890046 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2424"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6814" version="3" class="vulnerability">
      <metadata>
        <title>Windows Kernel Null Pointer Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0234" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0234"/>
        <description>The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 does not properly validate a registry-key argument to an unspecified system call, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Null Pointer Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-13T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-04-15T10:42:26.108-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:27.323-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:12.402-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4 or later">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 5.0.2195.7376" test_ref="oval:org.mitre.oval:tst:11458"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 5.1.2600.3670" test_ref="oval:org.mitre.oval:tst:11347"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 5.1.2600.5938" test_ref="oval:org.mitre.oval:tst:11896"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is less than 5.2.3790.4666" test_ref="oval:org.mitre.oval:tst:11857"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Server 2003 ia64 SP2">
          <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          <criterion comment="The version of Ntkrnlmp.exe is less than 5.2.3790.4666" test_ref="oval:org.mitre.oval:tst:11611"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6000.16000" test_ref="oval:org.mitre.oval:tst:10882"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6000.17021" test_ref="oval:org.mitre.oval:tst:11259"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:10762"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6000.21226" test_ref="oval:org.mitre.oval:tst:11841"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6001.18000" test_ref="oval:org.mitre.oval:tst:10821"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6001.18427" test_ref="oval:org.mitre.oval:tst:11737"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:10407"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6001.22636" test_ref="oval:org.mitre.oval:tst:11674"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6002.18000" test_ref="oval:org.mitre.oval:tst:10870"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6002.18209" test_ref="oval:org.mitre.oval:tst:11433"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10581"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6002.22341" test_ref="oval:org.mitre.oval:tst:11585"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6793" version="3" class="vulnerability">
      <metadata>
        <title>Windows Kernel Registry Key Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0238" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0238"/>
        <description>Unspecified vulnerability in registry-key validation in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Vista Gold allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Registry Key Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-13T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-04-15T10:42:27.675-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:26.243-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:11.141-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4 or later">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 5.0.2195.7376" test_ref="oval:org.mitre.oval:tst:11458"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 5.1.2600.3670" test_ref="oval:org.mitre.oval:tst:11347"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 5.1.2600.5938" test_ref="oval:org.mitre.oval:tst:11896"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is less than 5.2.3790.4666" test_ref="oval:org.mitre.oval:tst:11857"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Server 2003 ia64 SP2">
          <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          <criterion comment="The version of Ntkrnlmp.exe is less than 5.2.3790.4666" test_ref="oval:org.mitre.oval:tst:11611"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - GDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6000.16000" test_ref="oval:org.mitre.oval:tst:10882"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6000.17021" test_ref="oval:org.mitre.oval:tst:11259"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - LDR">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:10762"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6000.21226" test_ref="oval:org.mitre.oval:tst:11841"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6787" version="10" class="vulnerability">
      <metadata>
        <title>WinVerifyTrust Signature Validation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Authenticode Signature Verification</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0486" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0486"/>
        <description>The WinVerifyTrust function in Authenticode Signature Verification 5.1, 6.0, and 6.1 in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly use unspecified fields in a file digest, which allows user-assisted remote attackers to execute arbitrary code via a modified (1) Portable Executable (PE) or (2) cabinet (aka .CAB) file that incorrectly appears to have a valid signature, aka "WinVerifyTrust Signature Validation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-13T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-04-15T10:41:56.734-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:25.389-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:10.246-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:01.384-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:01.384-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:27.300-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4525 - contains tests with modified comments and all dependences" date="2014-02-13T12:19:00.287-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:23:13.423-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:17.736-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6787 - extended definitions of OS are without SP checks" date="2014-07-28T17:49:00.293-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:51:15.000-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:19.674-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <criterion comment="the version of wintrust.dll is less than 5.131.2195.7375" test_ref="oval:org.mitre.oval:tst:11686"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86)">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="the version of wintrust.dll is less than 5.131.2600.3661" test_ref="oval:org.mitre.oval:tst:11304"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86)">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="the version of wintrust.dll is less than 5.131.2600.5922" test_ref="oval:org.mitre.oval:tst:11690"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <criterion comment="the version of wintrust.dll is less than 5.131.3790.4642" test_ref="oval:org.mitre.oval:tst:11359"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="the version of wintrust.dll is less than 6.0.6000.16984" test_ref="oval:org.mitre.oval:tst:11719"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="the version of wintrust.dll is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:11349"/>
          <criterion comment="the version of wintrust.dll is less than 6.0.6000.21186" test_ref="oval:org.mitre.oval:tst:11492"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64, Server 2008 32bit/x64/ia64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of wintrust.dll is less than 6.0.6001.18387" test_ref="oval:org.mitre.oval:tst:11262"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64, Server 2008 32bit/x64/ia64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of wintrust.dll is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:11526"/>
          <criterion comment="the version of wintrust.dll is less than 6.0.6001.22588" test_ref="oval:org.mitre.oval:tst:11567"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64, Server 2008 32bit/x64/ia64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 32bit/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of wintrust.dll is less than 6.0.6002.18169" test_ref="oval:org.mitre.oval:tst:11040"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64, Server 2008 32bit/x64/ia64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 32bit/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of wintrust.dll is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:11196"/>
          <criterion comment="the version of wintrust.dll is less than 6.0.6002.22293" test_ref="oval:org.mitre.oval:tst:11738"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="the version of wintrust.dll is less than 6.1.7600.16493" test_ref="oval:org.mitre.oval:tst:11401"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criterion comment="the version of wintrust.dll is greater than or equal 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:11722"/>
          <criterion comment="the version of wintrust.dll is less than 6.1.7600.20605" test_ref="oval:org.mitre.oval:tst:11330"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6734" version="10" class="vulnerability">
      <metadata>
        <title>Outlook Express and Windows Mail Integer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Outlook Express</product>
          <product>Microsoft Windows Mail</product>
          <product>Microsoft Windows Live Mail</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0816" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0816"/>
        <description>Integer overflow in inetcomm.dll in Microsoft Outlook Express 5.5 SP2, 6, and 6 SP1; Windows Live Mail on Windows XP SP2 and SP3, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7; and Windows Mail on Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote e-mail servers and man-in-the-middle attackers to execute arbitrary code via a crafted (1) POP3 or (2) IMAP response, as demonstrated by a certain +OK response on TCP port 110, aka "Outlook Express and Windows Mail Integer Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-11T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-05-12T12:23:25.542-04:00">DRAFT</status_change>
            <status_change date="2010-05-31T04:00:28.757-04:00">INTERIM</status_change>
            <status_change date="2010-06-21T04:00:05.608-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:06.244-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:06.244-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:24.920-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6734 - Correcting incorrect references to 64-bit Itanium XP." date="2012-08-23T17:47:00.168-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-08-23T17:52:29.064-04:00">INTERIM</status_change>
            <status_change date="2012-09-10T04:01:08.691-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6734 - extended definitions of OS are without SP checks" date="2014-07-28T17:49:00.293-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:51:13.458-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:18.815-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Microsoft Outlook Express 5.5 SP2 on Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Outlook Express 5.5 SP2 is installed." definition_ref="oval:org.mitre.oval:def:504"/>
          <criterion comment="the version of Inetcomm.dll is less than 5.50.5010.200" test_ref="oval:org.mitre.oval:tst:11816"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Outlook Express 6 SP1 on Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Outlook Express 6 SP1 is installed." definition_ref="oval:org.mitre.oval:def:488"/>
          <criterion comment="the version of Inetcomm.dll is less than 6.0.2800.2001" test_ref="oval:org.mitre.oval:tst:11216"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Outlook Express 6 on Windows XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Outlook Express 6.0 for Windows XP/2003 is installed" definition_ref="oval:org.mitre.oval:def:208"/>
          <criterion comment="the version of Inetcomm.dll is less than 6.0.2900.3664" test_ref="oval:org.mitre.oval:tst:11320"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Outlook Express 6 on Windows XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Outlook Express 6.0 for Windows XP/2003 is installed" definition_ref="oval:org.mitre.oval:def:208"/>
          <criterion comment="the version of Inetcomm.dll is less than 6.0.2900.5931" test_ref="oval:org.mitre.oval:tst:10972"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Outlook Express 6 on Windows XP (64-bit), Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP (64-bit), Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Outlook Express 6.0 for Windows XP/2003 is installed" definition_ref="oval:org.mitre.oval:def:208"/>
          <criterion comment="the version of Inetcomm.dll is less than 6.0.3790.4657" test_ref="oval:org.mitre.oval:tst:11267"/>
        </criteria>
        <criteria operator="AND" comment="Windows Mail on Windows Vista x86/x64, Windows Server 2008 x86/x64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Windows Mail is installed" definition_ref="oval:org.mitre.oval:def:2058"/>
          <criterion comment="the version of Inetcomm.dll is less than 6.0.6001.18416" test_ref="oval:org.mitre.oval:tst:11337"/>
        </criteria>
        <criteria operator="AND" comment="Windows Mail on Windows Vista x86/x64, Windows Server 2008 x86/x64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Windows Mail is installed" definition_ref="oval:org.mitre.oval:def:2058"/>
          <criterion comment="the version of Inetcomm.dll is less than 6.0.6001.22621" test_ref="oval:org.mitre.oval:tst:11718"/>
          <criterion comment="the version of Inetcomm.dll is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:11476"/>
        </criteria>
        <criteria operator="AND" comment="Windows Mail on Windows Vista x86/x64, Windows Server 2008 x86/x64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Windows Mail is installed" definition_ref="oval:org.mitre.oval:def:2058"/>
          <criterion comment="The version of Inetcomm.dll is less than 6.0.6002.18197" test_ref="oval:org.mitre.oval:tst:11803"/>
        </criteria>
        <criteria operator="AND" comment="Windows Mail on Windows Vista x86/x64, Windows Server 2008 x86/x64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Windows Mail is installed" definition_ref="oval:org.mitre.oval:def:2058"/>
          <criterion comment="the version of Inetcomm.dll is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:11786"/>
          <criterion comment="The version of Inetcomm.dll is less than 6.0.6002.22325" test_ref="oval:org.mitre.oval:tst:11524"/>
        </criteria>
        <criteria operator="AND" comment="Windows Mail Windows Server 2008 ia64 - GDR">
          <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          <extend_definition comment="Microsoft Windows Mail is installed" definition_ref="oval:org.mitre.oval:def:2058"/>
          <criterion comment="the version of Inetcomm.dll is less than 6.0.6001.18427" test_ref="oval:org.mitre.oval:tst:11799"/>
        </criteria>
        <criteria operator="AND" comment="Windows Mail on Windows Server 2008 ia64 - LDR">
          <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          <extend_definition comment="Microsoft Windows Mail is installed" definition_ref="oval:org.mitre.oval:def:2058"/>
          <criterion comment="the version of Inetcomm.dll is less than 6.0.6001.22636" test_ref="oval:org.mitre.oval:tst:11536"/>
          <criterion comment="the version of Inetcomm.dll is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:11476"/>
        </criteria>
        <criteria operator="AND" comment="Windows Mail on Windows Server 2008 ia64 - GDR">
          <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          <extend_definition comment="Microsoft Windows Mail is installed" definition_ref="oval:org.mitre.oval:def:2058"/>
          <criterion comment="The version of Inetcomm.dll is less than 6.0.6002.18209" test_ref="oval:org.mitre.oval:tst:11316"/>
        </criteria>
        <criteria operator="AND" comment="Windows Mail on Windows Server 2008 ia64 - LDR">
          <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          <extend_definition comment="Microsoft Windows Mail is installed" definition_ref="oval:org.mitre.oval:def:2058"/>
          <criterion comment="the version of Inetcomm.dll is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:11786"/>
          <criterion comment="The version of Inetcomm.dll is less than 6.0.6002.22341" test_ref="oval:org.mitre.oval:tst:11688"/>
        </criteria>
        <criteria operator="AND" comment="Windows Mail on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - GDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Windows Mail is installed" definition_ref="oval:org.mitre.oval:def:2058"/>
          <criterion comment="the version of Inetcomm.dll is less than 6.1.7600.16543" test_ref="oval:org.mitre.oval:tst:11904"/>
        </criteria>
        <criteria operator="AND" comment="Windows Mail on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - LDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Windows Mail is installed" definition_ref="oval:org.mitre.oval:def:2058"/>
          <criterion comment="the version of Inetcomm.dll is greater than or equal 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:11895"/>
          <criterion comment="the version of Inetcomm.dll is less than 6.1.7600.20659" test_ref="oval:org.mitre.oval:tst:11232"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:673" version="3" class="vulnerability">
      <metadata>
        <title>Windows 2000 Kernel Elevation of Privilege Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference ref_id="CVE-2006-3444" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3444" source="CVE"/>
        <description>Unspecified vulnerability in the kernel in Microsoft Windows 2000 SP4, probably a buffer overflow, allows local users to obtain privileges via unspecified vectors involving an "unchecked buffer."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:34.552-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:46.655-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:673 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:06:40.242-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:40.449-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
        <criterion comment="The version of Ntoskrnl.exe is less than 5.0.2195.7098." test_ref="oval:org.mitre.oval:tst:46"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6686" version="9" class="vulnerability">
      <metadata>
        <title>HTML Element Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1260" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1260"/>
        <description>The IE8 Developer Toolbar in Microsoft Internet Explorer 8 SP1, SP2, and SP3 allows user-assisted remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "HTML Element Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-06-14T11:32:18.494-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:48:45.183-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:07.291-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:10804 - Updated comments to test ID's tst:10804 &amp; tst:10787. And also corrected the version to state ID's ste:6638 &amp; ste:6932 by adding comments according to the MS Bulletins." date="2011-07-18T15:25:00.211-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-07-18T15:27:05.498-04:00">INTERIM</status_change>
            <status_change date="2011-08-08T04:00:51.313-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:09.712-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:09.712-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:20.184-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6686 - extended definitions of OS are without SP checks" date="2014-07-28T17:36:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:37:55.936-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:17.179-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 8 on XP x86/x64, Server 2003 x86/x64/ia64 - GDR">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18928" test_ref="oval:org.mitre.oval:tst:27064"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on XP x86/x64, Server 2003 x86/x64/ia64 - LDR">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.23019" test_ref="oval:org.mitre.oval:tst:27361"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64 - GDR">
          <criteria operator="OR" comment="Vista x86/x64, all Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.18928" test_ref="oval:org.mitre.oval:tst:27064"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64 - LDR">
          <criteria operator="OR" comment="Vista x86/x64, all Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
          <criterion comment="Mshtml.dll version is less than 8.0.6001.23019" test_ref="oval:org.mitre.oval:tst:27361"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - GDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.16588" test_ref="oval:org.mitre.oval:tst:27609"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64 - LDR">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:10804"/>
          <criterion comment="Mshtml.dll version is less than 8.0.7600.20708" test_ref="oval:org.mitre.oval:tst:27372"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6653" version="13" class="vulnerability">
      <metadata>
        <title>Windows Media Player Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Windows Media Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2745" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2745"/>
        <description>Microsoft Windows Media Player (WMP) 9 through 12 does not properly deallocate objects during a browser reload action, which allows user-assisted remote attackers to execute arbitrary code via crafted media content referenced in an HTML document, aka "Windows Media Player Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-12T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-10-26T21:07:20.616-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:28.287-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:43.626-05:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:03.494-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:03.494-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:17.851-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6653 - Correcting incorrect references to 64-bit Itanium XP." date="2012-08-23T17:47:00.168-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-08-23T17:53:00.179-04:00">INTERIM</status_change>
            <status_change date="2012-09-10T04:01:04.621-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:10251 - office 2007 more changed vulnerabilities" date="2014-05-30T10:22:00.303-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-30T10:26:30.362-04:00">INTERIM</status_change>
            <status_change date="2014-06-16T04:00:17.581-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6653 - extended definitions of OS are without SP checks" date="2014-07-28T17:49:00.293-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:51:12.123-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:16.531-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:20961 - MS bulletins for the month of June 2015" date="2015-06-18T10:14:00.489-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-06-18T10:17:12.835-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:46.396-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Media Player 9 on Windows XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Windows Media Player v9 is installed." definition_ref="oval:org.mitre.oval:def:2147"/>
          <criterion comment="the version of Wmp.dll is less than 9.0.0.4510" test_ref="oval:org.mitre.oval:tst:21458"/>
        </criteria>
        <criteria operator="AND" comment="Windows Media Player 10 on Windows XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Windows Media Player v10 is installed." definition_ref="oval:org.mitre.oval:def:2172"/>
          <criterion comment="the version of Wmp.dll is less than 10.0.0.4081" test_ref="oval:org.mitre.oval:tst:21227"/>
        </criteria>
        <criteria operator="AND" comment="Windows Media Player 10 on Windows XP (x64-bit) or Windows Server 2003 (x64-bit)">
          <criteria operator="OR" comment="Windows XP (x64-bit) or Windows Server 2003 (x64-bit)">
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Windows Media Player v10 is installed." definition_ref="oval:org.mitre.oval:def:2172"/>
          <criterion comment="the version of Wwmp.dll is less than 10.0.0.4008" test_ref="oval:org.mitre.oval:tst:20961"/>
        </criteria>
        <criteria operator="AND" comment="Windows Media Player 10 on windows server 2003 x86">
          <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
          <extend_definition comment="Windows Media Player v10 is installed." definition_ref="oval:org.mitre.oval:def:2172"/>
          <criterion comment="the version of Wmp.dll is less than 10.0.0.4008" test_ref="oval:org.mitre.oval:tst:21417"/>
        </criteria>
        <criteria operator="AND" comment="Windows Media Player 11 on Windows XP x86 or windows XP (x64-bit)">
          <criteria operator="OR" comment="Windows XP x86 or windows XP (x64-bit)">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Windows Media Player v11 is installed." definition_ref="oval:org.mitre.oval:def:2126"/>
          <criterion comment="the version of Wmp.dll is less than 11.0.5721.5280" test_ref="oval:org.mitre.oval:tst:21412"/>
        </criteria>
        <criteria operator="AND" comment="Windows Media Player 11 on Windows Vista/Server 2008 (32-bit)/(64-bit)/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Windows Media Player v11 is installed." definition_ref="oval:org.mitre.oval:def:2126"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of Wmp.dll is less than 11.0.6001.7010" test_ref="oval:org.mitre.oval:tst:21303"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Spwmp.dll version is greater than or equal to 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:10251"/>
              <criterion comment="the version of Wmp.dll is less than 11.0.6001.7118" test_ref="oval:org.mitre.oval:tst:21416"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows Media Player 11 on Windows Vista /Server 2008 (32-bit)/(64-bit)/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Windows Media Player v11 is installed." definition_ref="oval:org.mitre.oval:def:2126"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of Wmp.dll is less than 11.0.6002.18311" test_ref="oval:org.mitre.oval:tst:21253"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of Wmp.dll is greater than or equal 11.0.6002.22000" test_ref="oval:org.mitre.oval:tst:21257"/>
              <criterion comment="the version of Wmp.dll is less than 11.0.6002.22486" test_ref="oval:org.mitre.oval:tst:21471"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows Media Player 12 on Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="7 x86/x64, Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Windows Media Player v12 is installed." definition_ref="oval:org.mitre.oval:def:7384"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="The version of Wmp.dll is less than 12.0.7600.16667" test_ref="oval:org.mitre.oval:tst:20189"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="The version of Wmp.dll is greater than or equal 12.0.7600.20000" test_ref="oval:org.mitre.oval:tst:20141"/>
              <criterion comment="The version of Wmp.dll is less than 12.0.7600.20792" test_ref="oval:org.mitre.oval:tst:20478"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7384" version="15" class="inventory">
      <metadata>
        <title>Windows Media Player v12 is installed.</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Windows Media Player 12</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:windows_media_player:12"/>
        <description>Windows Media Player v12 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-12T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-10-26T21:07:20.441-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:47.820-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:53.335-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7384 - On definition oval:org.mitre.oval:def:7384  I changed the affected platform from &quot;Microsoft Windows 2008&quot; to &quot;Microsoft Windows Server 2008&quot;" date="2011-05-12T10:52:00.860-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2011-05-12T10:58:08.668-04:00">INTERIM</status_change>
            <status_change date="2011-05-30T04:00:53.617-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7384 - Modifications vary from minor OVAL title/description changes to suggesting an alternative CPE name to use." date="2011-09-28T11:29:00.976-04:00">
              <contributor organization="The MITRE Corporation">David Rothenberg</contributor>
            </modified>
            <status_change date="2011-09-28T11:33:25.594-04:00">INTERIM</status_change>
            <status_change date="2011-10-17T04:00:25.649-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:03.509-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:03.509-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:57.287-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7384 - inventory for Windows Media Player 12" date="2013-09-13T13:51:00.711-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-09-13T13:52:27.920-04:00">INTERIM</status_change>
            <status_change date="2013-09-30T04:01:37.481-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:86182 - replaced all similar objects with oval:org.mitre.oval:obj:26224" date="2014-04-10T08:55:00.661-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-04-10T08:58:20.278-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:07:40.186-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:7384 - Modified Win Media Player inventories: Fixed product version info" date="2015-04-10T10:03:00.585-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-04-10T10:05:26.566-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:28.008-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Check if Windows Media Player version is greater than or equal to 12.0.0.0" test_ref="oval:org.mitre.oval:tst:86727"/>
        <criterion comment="Check if Windows Media Player version is less than 13.0.0.0" test_ref="oval:org.mitre.oval:tst:86182"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6650" version="3" class="vulnerability">
      <metadata>
        <title>Buffer overflow vulnerability in kavfm.sys in Kingsoft Antivirus 2010.7.30.201 and earlier</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Kingsoft Antivirus</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3396" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3396"/>
        <description>Buffer overflow in kavfm.sys in Kingsoft Antivirus 2010.04.26.648 and earlier allows local users to execute arbitrary code via a long argument to IOCTL 0x80030004.  NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-22T18:45:49">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-10-25T10:41:08.637-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:27.886-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:43.283-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Kingsoft Antivirus is installed" definition_ref="oval:org.mitre.oval:def:6932"/>
        <criterion comment="Check if the version of kavfm.sys in Kingsoft Antivirus is less than or equal to 2010.7.30.201" test_ref="oval:org.mitre.oval:tst:19977"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6932" version="3" class="inventory">
      <metadata>
        <title>Kingsoft Antivirus is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Kingsoft Antivirus</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:kingsoftsecurity:kingsoft_antivirus"/>
        <description>Kingsoft Antivirus is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-22T18:45:49">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-10-25T10:41:08.123-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:36.902-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:48.331-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Kingsoft Antivirus is installed" test_ref="oval:org.mitre.oval:tst:20507"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6641" version="5" class="vulnerability">
      <metadata>
        <title>MJPEG Media Decompression Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Quartz.dll (DirectShow)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1880" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1880"/>
        <description>Unspecified vulnerability in Quartz.dll for DirectShow on Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1, and Server 2008 allows remote attackers to execute arbitrary code via a media file with crafted compression data, aka "MJPEG Media Decompression Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-06-14T11:31:43.064-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:48:42.562-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:04.986-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6641 - extended definitions of OS are without SP checks" date="2014-07-28T17:36:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:37:57.696-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:16.089-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 / Quartz in DirectX 9.0">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <criterion comment="DirectX 9.0x Installed" test_ref="oval:org.mitre.oval:tst:601"/>
          <criterion comment="the version of Quartz.dll is less than 6.5.1.914" test_ref="oval:org.mitre.oval:tst:27014"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) / Quartz">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="the version of Quartz.dll is less than 6.5.2600.3665" test_ref="oval:org.mitre.oval:tst:27701"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) / Quartz">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="the version of Quartz.dll is less than 6.5.2600.5933" test_ref="oval:org.mitre.oval:tst:27719"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64, Server 2003 x86/x64/ia64 / Quartz">
          <criteria operator="OR" comment="XP x64, Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <criterion comment="the version of Quartz.dll is less than 6.5.3790.4660" test_ref="oval:org.mitre.oval:tst:27493"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64, Server 2008 32bit/x64/ia64 - GDR / Quartz">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of Quartz.dll is less than 6.6.6001.18461" test_ref="oval:org.mitre.oval:tst:27630"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64, Server 2008 32bit/x64/ia64 - LDR / Quartz">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of Quartz.dll is less than 6.6.6001.22672" test_ref="oval:org.mitre.oval:tst:27567"/>
          <criterion comment="the version of Quartz.dll is greater than or equal 6.6.6001.22000" test_ref="oval:org.mitre.oval:tst:20940"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6639" version="1" class="vulnerability">
      <metadata>
        <title>Local Security Authority Subsystem Service Resource Exhaustion Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3675" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3675"/>
        <description>LSASS.exe in the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote authenticated users to cause a denial of service (CPU consumption) via a malformed ISAKMP request over IPsec, aka "Local Security Authority Subsystem Service Resource Exhaustion Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-09T17:00:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2009-12-11T11:34:15.761-05:00">DRAFT</status_change>
            <status_change date="2009-12-28T04:00:39.981-05:00">INTERIM</status_change>
            <status_change date="2010-01-18T04:00:13.327-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Oakley.dll is less than 5.0.2195.7343" test_ref="oval:org.mitre.oval:tst:11206"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="the version of Oakley.dll is less than 5.1.2600.3632" test_ref="oval:org.mitre.oval:tst:11233"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of Oakley.dll is less than 5.1.2600.5886" test_ref="oval:org.mitre.oval:tst:10926"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of Oakley.dll is less than 5.2.3790.4600" test_ref="oval:org.mitre.oval:tst:10247"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6621" version="1" class="vulnerability" deprecated="true">
      <metadata>
        <title>ATL COM Initialization Vulnerability (CVE-2009-2493)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2493" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2493"/>
        <description>The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1; and Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2; does not properly restrict use of OleLoadFromStream in instantiating objects from data streams, which allows remote attackers to execute arbitrary code via a crafted HTML document with an ATL (1) component or (2) control, related to ATL headers and bypassing security policies, aka "ATL COM Initialization Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-08T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-12-11T11:36:01.737-05:00">DRAFT</status_change>
            <status_change date="2009-12-28T04:00:38.986-05:00">INTERIM</status_change>
            <modified comment="Deprecated after consolidating other definitions for the same CVE. The new consolidated definition is oval:org.mitre.oval:def:6716" date="2010-01-03T18:00:11.513-04:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2010-01-03T18:00:11.513-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="Mshtml.dll version is less than 5.0.3882.2700" test_ref="oval:org.mitre.oval:tst:11030"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1642" test_ref="oval:org.mitre.oval:tst:10363"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3640" test_ref="oval:org.mitre.oval:tst:11188"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5897" test_ref="oval:org.mitre.oval:tst:11032"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4611" test_ref="oval:org.mitre.oval:tst:11149"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6600" version="4" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP4 Install Engine Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0216" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0216"/>
        <description>Integer overflow in the Install Engine (inseng.dll) for Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious website or HTML email with a long .CAB file name, which triggers the integer overflow when calculating a buffer length and leads to a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-25T04:23:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-27T01:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-17T10:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed ste:2614: set datatype to version.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:54:00.319-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:59:43.980-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:51.304-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:50.139-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:25.333-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3534.2800" negate="false" test_ref="oval:org.mitre.oval:tst:519"/>
          <criterion comment="the patch kb834707-ie501sp4 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:518"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:66" version="6" class="vulnerability">
      <metadata>
        <title>IIS ASP Function Cross-site Scripting</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0223" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0223"/>
        <description>Cross-site scripting vulnerability (XSS) in the ASP function responsible for redirection in Microsoft Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to embed a URL containing script in a redirection message.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified date="2005-03-07T12:00:00.000-04:00" comment="modified wrt-222 - changed pattern match">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-03-09T07:55:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-29T07:59:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Multiple corrections and update to POSIX compatibility for ste:2878" date="2010-11-29T16:13:00.904-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-11-29T16:14:04.957-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:01:05.408-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:25.719-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:03:19.519-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="File %windir%\system32\inetsrv\asp.dll version is less than 5.0.2195.6672" negate="false" test_ref="oval:org.mitre.oval:tst:2988"/>
        <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
        <criterion comment="SP4 or later Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3073"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6579" version="5" class="vulnerability">
      <metadata>
        <title>Windows (ME, NT, 2K, XP), IE v6,SP1 CSS Heap Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0842" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0842"/>
        <description>Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from "memory corruption") via certain malformed Cascading Style Sheet (CSS) elements that trigger heap-based buffer overflows, as demonstrated using the "&lt;STYLE>@;/*" string, possibly due to a missing comment terminator that may cause an invalid length to trigger a large memory copy operation, aka the "CSS Heap Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-19T04:56:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-20T02:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-27T10:50:00.000-04:00" comment="modified wft-564 - Changed test to match comment">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:46:07.043-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:50.989-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:57.699-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:25.262-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1476" negate="false" test_ref="oval:org.mitre.oval:tst:856"/>
          <criterion comment="the patch kb834707 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:855"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:653" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 ASN.1 Library Integer Overflow Vulnerabilities</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft ASN.1 Library</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0818" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0818"/>
        <description>Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executables and libraries on Windows NT 4.0, 2000, and XP, allow remote attackers to execute arbitrary code via ASN.1 BER encodings with (1) very large length fields that cause arbitrary heap data to be overwritten, or (2) modified bit strings.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="the version of msasn1.dll is less than 5.0.2195.6823" negate="false" test_ref="oval:org.mitre.oval:tst:2469"/>
        <criterion comment="the patch kb828028 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2468"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6524" version="1" class="vulnerability">
      <metadata>
        <title>Maxthon Browser Cross-Site Scripting Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Maxthon Browser</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3018" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3018"/>
        <description>Maxthon Browser 3.0.0.145 Alpha with Ultramode does not properly block javascript: and data: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header that contains a javascript: URI, (2) entering a javascript: URI when specifying the content of a Refresh header, (3) injecting a Refresh header that contains JavaScript sequences in a data:text/html URI, or (4) entering a data:text/html URI with JavaScript sequences when specifying the content of a Refresh header; does not properly block data: URIs in Location headers in HTTP responses, which allows user-assisted remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (5) injecting a Location header that contains JavaScript sequences in a data:text/html URI or (6) entering a data:text/html URI with JavaScript sequences when specifying the content of a Location header; and does not properly handle javascript: URIs in HTML links within (a) 301 and (b) 302 error documents sent from web servers, which allows user-assisted remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (7) injecting a Location HTTP response header or (8) specifying the content of a Location HTTP response header.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-23T10:27:31.430-04:00">
              <contributor organization="SecPod Technologies">Sharath S</contributor>
            </submitted>
            <status_change date="2009-11-23T14:56:41.355-05:00">DRAFT</status_change>
            <status_change date="2009-12-14T04:00:14.134-05:00">INTERIM</status_change>
            <status_change date="2010-01-04T04:01:52.829-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Maxthon Browser is installed" definition_ref="oval:org.mitre.oval:def:6262"/>
        <criterion comment="Maxthon Browser version is equal to 3.0.0.145" test_ref="oval:org.mitre.oval:tst:10779"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6510" version="8" class="vulnerability">
      <metadata>
        <title>Microsoft Silverlight and Microsoft .NET Framework CLR Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft .NET Framework</product>
          <product>Microsoft Silverlight</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2497" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2497"/>
        <description>The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0, 2.0 SP1, 2.0 SP2, 3.5, and 3.5 SP1, and Silverlight 2, does not properly handle interfaces, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP), (2) a crafted Silverlight application, (3) a crafted ASP.NET application, or (4) a crafted .NET Framework application, aka "Microsoft Silverlight and Microsoft .NET Framework CLR Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-13T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-10-22T17:36:56.292-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:01:11.485-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:53.775-05:00">ACCEPTED</status_change>
            <modified comment="Updated to reference obj:2009" date="2009-12-01T17:59:00.669-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2009-12-01T18:00:44.002-05:00">INTERIM</status_change>
            <modified comment="Updated to reference obj:2009" date="2009-12-01T18:00:00.766-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <modified comment="Updated to reference obj:2009" date="2009-12-01T18:01:00.229-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <modified comment="Updated to reference obj:2009" date="2009-12-01T18:01:00.547-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2009-12-21T04:01:02.891-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6510 - Updated defs for MS09-061 - updated criteria and modified the GDR/LDR format." date="2011-01-31T17:30:00.645-05:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-01-31T17:33:03.553-05:00">INTERIM</status_change>
            <status_change date="2011-02-21T04:01:11.266-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6510 - Modified criteria to match MS bulletin" date="2014-06-13T17:54:00.121-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T17:57:28.713-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:11:18.906-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6510 - extended definitions of OS are without SP checks" date="2014-07-28T17:36:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:37:53.321-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:14.911-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment=".NET Framework 2.0 on Windows Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 (Original RTM or later) is installed" definition_ref="oval:org.mitre.oval:def:1934"/>
          <criterion comment="the version of Mscorlib.dll is less than 2.0.50727.1003" test_ref="oval:org.mitre.oval:tst:21588"/>
        </criteria>
        <criteria operator="AND" comment=".NET Framework 2.0 SP1">
          <criteria operator="OR" comment="OS section">
            <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:6428"/>
          <criterion comment="the version of Mscorlib.dll is less than 2.0.50727.1873" test_ref="oval:org.mitre.oval:tst:10790"/>
        </criteria>
        <criteria operator="AND" comment=".NET Framework 3.5">
          <criteria operator="OR" comment="OS section">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 Original Release is installed" definition_ref="oval:org.mitre.oval:def:6689"/>
          <criterion comment="the version of Mscorlib.dll is less than 2.0.50727.1873" test_ref="oval:org.mitre.oval:tst:10790"/>
        </criteria>
        <criteria operator="AND" comment=".NET Framework 2.0 SP2 on Windows 2000, XP, Server 2003, Vista, Server 2008">
          <criteria operator="OR" comment="OS section">
            <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
          <criteria operator="OR" comment="GDR or LDR Service Branch">
            <criterion comment="the version of Mscorlib.dll is less than 2.0.50727.3603" test_ref="oval:org.mitre.oval:tst:10670"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of Mscorlib.dll is greater than or equal to 2.0.50727.4000" test_ref="oval:org.mitre.oval:tst:41709"/>
              <criterion comment="Mscorlib.dll is less than 2.0.50727.4062" test_ref="oval:org.mitre.oval:tst:21461"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET Framework 3.5 SP1">
          <criteria operator="OR" comment="OS section">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="GDR or LDR Service Branch">
            <criterion comment="the version of Mscorlib.dll is less than 2.0.50727.3603" test_ref="oval:org.mitre.oval:tst:10670"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of Mscorlib.dll is greater than or equal to 2.0.50727.4000" test_ref="oval:org.mitre.oval:tst:41709"/>
              <criterion comment="Mscorlib.dll is less than 2.0.50727.4062" test_ref="oval:org.mitre.oval:tst:21461"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET Framework 2.0 SP2 on Vista x86/x64, Windows Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
          <criteria operator="OR" comment="GDR or LDR">
            <criterion comment="the version of Mscorlib.dll is less than 2.0.50727.4200" test_ref="oval:org.mitre.oval:tst:10981"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of Mscorlib.dll is less than 2.0.50727.4400" test_ref="oval:org.mitre.oval:tst:10805"/>
              <criterion comment="the version of Mscorlib.dll is greater than or equal to 2.0.50727.4300" test_ref="oval:org.mitre.oval:tst:41546"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6689" version="7" class="inventory">
      <metadata>
        <title>Microsoft .NET Framework 3.5 Original Release is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft .NET Framework 3.5</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:.net_framework:3.5:-"/>
        <description>Microsoft .NET Framework 3.5 Original Release is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-06-14T11:33:21.235-04:00">DRAFT</status_change>
            <status_change date="2010-06-29T11:48:45.767-04:00">INTERIM</status_change>
            <status_change date="2010-07-19T04:00:07.908-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6689 - Updated to check registry keys instead of version of DLL." date="2011-01-13T14:14:00.592-05:00">
              <contributor organization="The MITRE Corporation">Nate Przybyszewski</contributor>
            </modified>
            <status_change date="2011-01-13T14:16:15.895-05:00">INTERIM</status_change>
            <status_change date="2011-01-31T04:00:15.652-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6689 - .NET Framework inventories with modified products." date="2014-03-18T14:31:00.962-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-18T14:33:24.594-04:00">INTERIM</status_change>
            <status_change date="2014-04-07T04:06:56.217-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Is the Microsoft .NET Framework 3.5 installed" test_ref="oval:org.mitre.oval:tst:42024"/>
        <criterion comment="Is the Microsoft .NET Framework 3.5 the Original Release" test_ref="oval:org.mitre.oval:tst:42129"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6158" version="7" class="inventory">
      <metadata>
        <title>Microsoft .NET Framework 2.0 Service Pack 2 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft .NET Framework 2.0</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:.net_framework:2.0:sp2"/>
        <description>Microsoft .NET Framework 2.0 Service Pack 2 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-13T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-10-22T17:36:54.998-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:38.208-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:23.181-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:10028 - Created OVAL vulnerability definition for MS10-070" date="2011-02-28T09:25:00.601-05:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-02-28T09:32:44.470-05:00">INTERIM</status_change>
            <status_change date="2011-03-21T04:00:14.972-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:10028 - New Definitions for April 2011 Patch Tuesday" date="2011-04-18T00:17:00.032-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-04-18T00:18:31.230-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:38.435-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6158 - .NET Framework inventories with modified products." date="2014-03-18T14:31:00.962-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-18T14:33:24.166-04:00">INTERIM</status_change>
            <status_change date="2014-04-07T04:06:55.839-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="The version of Mscorlib.dll is greater than or equal to 2.0.50727.3053" test_ref="oval:org.mitre.oval:tst:10028"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12542" version="7" class="inventory">
      <metadata>
        <title>Microsoft .NET Framework 3.5 SP1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft .NET Framework 3.5</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:.net_framework:3.5:sp1"/>
        <description>Microsoft .NET Framework 3.5 SP1 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2011-02-28T09:32:39.073-05:00">DRAFT</status_change>
            <status_change date="2011-03-21T04:00:12.747-04:00">INTERIM</status_change>
            <status_change date="2011-04-11T04:00:11.237-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:09.634-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:09.634-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:02:05.159-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:12542 - .NET Framework inventories with modified products." date="2014-03-18T14:31:00.962-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-18T14:33:24.958-04:00">INTERIM</status_change>
            <status_change date="2014-04-07T04:00:12.852-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Is the Microsoft .NET Framework 3.5 installed" test_ref="oval:org.mitre.oval:tst:42024"/>
        <criterion comment="Microsoft .NET Framework 3.5 SP1 is installed" test_ref="oval:org.mitre.oval:tst:42405"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6509" version="3" class="vulnerability">
      <metadata>
        <title>Avast! Home and Professional 'ashWsFtr.dll' Unspecified Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Avast! AntiVirus</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3524" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3524"/>
        <description>Unspecified vulnerability in ashWsFtr.dll in Avast! Home and Professional for Windows before 4.8.1356 has unknown impact and local attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-25T10:27:31.430-04:00">
              <contributor organization="SecPod Technologies">Sharath S</contributor>
            </submitted>
            <status_change date="2009-11-25T13:47:37.199-05:00">DRAFT</status_change>
            <status_change date="2009-12-14T04:00:13.761-05:00">INTERIM</status_change>
            <status_change date="2010-01-04T04:01:50.838-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:592 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:27:15.971-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:30.120-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Avast! AntiVirus is installed" definition_ref="oval:org.mitre.oval:def:6558"/>
        <criterion comment="Avast! version is less than 4.8.1356.0" test_ref="oval:org.mitre.oval:tst:10746"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6508" version="8" class="vulnerability">
      <metadata>
        <title>IIS FTP Service DoS Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2521" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2521"/>
        <description>Stack consumption vulnerability in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows remote authenticated users to cause a denial of service (daemon crash) via a list (ls) -R command containing a wildcard that references a subdirectory, followed by a .. (dot dot), aka "IIS FTP Service DoS Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-13T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-10-22T17:37:05.385-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:01:10.706-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:52.997-05:00">ACCEPTED</status_change>
            <modified comment="Updated the tests for the correct lower boundary file version for the Windows 7/2008 checks" date="2010-08-09T15:54:00.377-04:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2010-08-09T15:55:19.316-04:00">INTERIM</status_change>
            <modified comment="Merged LDR &amp;amp; GDR branches for several criteria to avoid duplicate object collection." date="2010-08-11T13:24:00.324-04:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2010-08-30T04:00:12.149-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6508 - October Patch Tuesday" date="2011-10-14T16:09:00.325-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-10-14T16:09:56.395-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:04:15.998-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6508 - extended definitions of OS are without SP checks" date="2014-07-28T17:36:00.492-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:37:55.073-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:14.592-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows 2000 - IIS 5.0 (FTP Service 5.0)">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft IIS 5.0 is installed" definition_ref="oval:org.mitre.oval:def:731"/>
          <criterion comment="The version of ftpsvc2.dll is less than 5.0.2195.7336" test_ref="oval:org.mitre.oval:tst:10425"/>
        </criteria>
        <criteria operator="AND" comment="Windows XP x86 - IIS 5.1 (FTP Service 5.1)">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft IIS 5.1 is installed" definition_ref="oval:org.mitre.oval:def:460"/>
          <criterion comment="The version of ftpsvc2.dll is less than 6.0.2600.3624" test_ref="oval:org.mitre.oval:tst:10973"/>
        </criteria>
        <criteria operator="AND" comment="Windows XP x86 - IIS 5.1 (FTP Service 5.1)">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft IIS 5.1 is installed" definition_ref="oval:org.mitre.oval:def:460"/>
          <criterion comment="The version of ftpsvc2.dll is less than 6.0.2600.5875" test_ref="oval:org.mitre.oval:tst:10691"/>
        </criteria>
        <criteria operator="AND" comment="Windows XP x64/Windows 2003 (x86/x64/ia64) - IIS 6.0 (FTP Service 6.0)">
          <criteria operator="OR" comment="Windows XP x64/Windows 2003 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft IIS 6.0 is installed" definition_ref="oval:org.mitre.oval:def:227"/>
          <criterion comment="The version of ftpsvc2.dll is less than 6.0.3790.4584" test_ref="oval:org.mitre.oval:tst:10767"/>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64 - IIS 7.0 (FTP Service 6.0)">
          <criteria operator="OR" comment="Windows Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft IIS 7.0 is installed" definition_ref="oval:org.mitre.oval:def:5377"/>
          <criterion comment="the version of ftpsvc2.dll is greater than or equal 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:10243"/>
          <criterion comment="The version of ftpsvc2.dll is less than 7.0.6000.16923" test_ref="oval:org.mitre.oval:tst:10891"/>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64 - IIS 7.0 (FTP Service 6.0)">
          <criteria operator="OR" comment="Windows Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft IIS 7.0 is installed" definition_ref="oval:org.mitre.oval:def:5377"/>
          <criterion comment="the version of ftpsvc2.dll is greater than or equal 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:10608"/>
          <criterion comment="The version of ftpsvc2.dll is less than 7.0.6000.21123" test_ref="oval:org.mitre.oval:tst:10591"/>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64, Windows Server 2008 x86/x64/ia64 - IIS 7.0 (FTP Service 6.0)">
          <criteria operator="OR" comment="Windows Vista x86/x64, Windows Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft IIS 7.0 is installed" definition_ref="oval:org.mitre.oval:def:5377"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="The version of ftpsvc2.dll is less than 7.0.6001.18327" test_ref="oval:org.mitre.oval:tst:10938"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of ftpsvc2.dll is greater than or equal 7.0.6001.22000" test_ref="oval:org.mitre.oval:tst:10894"/>
              <criterion comment="The version of ftpsvc2.dll is less than 7.0.6001.22516" test_ref="oval:org.mitre.oval:tst:10893"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64, Windows Server 2008 x86/x64/ia64 - IIS 7.0 (FTP Service 6.0)">
          <criteria operator="OR" comment="Windows Vista x86/x64, Windows Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft IIS 7.0 is installed" definition_ref="oval:org.mitre.oval:def:5377"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="The version of ftpsvc2.dll is less than 7.0.6002.18107" test_ref="oval:org.mitre.oval:tst:10962"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of ftpsvc2.dll is greater than or equal 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10338"/>
              <criterion comment="The version of ftpsvc2.dll is less than 7.0.6002.22219" test_ref="oval:org.mitre.oval:tst:10925"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6506" version="3" class="vulnerability">
      <metadata>
        <title>Windows Kernel Integer Underflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2515" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2515"/>
        <description>Integer underflow in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows local users to gain privileges via a crafted application that triggers an incorrect truncation of a 64-bit integer to a 32-bit integer, aka "Windows Kernel Integer Underflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-13T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-10-22T17:36:46.632-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:01:09.975-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:52.273-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6506 - For 2003 itanium platform, updated with the proper file (Ntkrnlmp.exe) as given in the bulletin" date="2011-10-04T13:19:00.233-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-10-04T13:20:38.483-04:00">INTERIM</status_change>
            <status_change date="2011-10-24T04:00:26.608-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 5.0.2195.7319" test_ref="oval:org.mitre.oval:tst:10573"/>
        </criteria>
        <criteria operator="AND" comment="Windows XP x86 SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 5.1.2600.3610" test_ref="oval:org.mitre.oval:tst:10847"/>
        </criteria>
        <criteria operator="AND" comment="Windows XP x86 SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 5.1.2600.5857" test_ref="oval:org.mitre.oval:tst:11004"/>
        </criteria>
        <criteria operator="AND" comment="Windows XP x64 SP2, Windows Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR" comment="OS check for Windows XP (x64) SP2 or Windows 2003">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is less than 5.2.3790.4566" test_ref="oval:org.mitre.oval:tst:10965"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Server 2003 ia64 SP2">
          <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          <criterion comment="the version of Ntkrnlmp.exe is less than 5.2.3790.4566" test_ref="oval:org.mitre.oval:tst:44068"/>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64">
          <criteria operator="OR" comment="OS check for Windows Vista (x86/x64)">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6000.16901" test_ref="oval:org.mitre.oval:tst:10944"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:10762"/>
              <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6000.21101" test_ref="oval:org.mitre.oval:tst:10113"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64 SP1, Windows Server 2008 x86/x64/ia64 SP1">
          <criteria operator="OR" comment="OS check for Windows Vista SP1 or 2008 Server">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6001.18304" test_ref="oval:org.mitre.oval:tst:10438"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:10407"/>
              <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6001.22489" test_ref="oval:org.mitre.oval:tst:10918"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64 SP2, Windows Server 2008 x86/x64/ia64 SP2">
          <criteria operator="OR" comment="OS check for Windows Vista SP2 or 2008 Server SP2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6002.18082" test_ref="oval:org.mitre.oval:tst:10866"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10581"/>
              <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6002.22191" test_ref="oval:org.mitre.oval:tst:10957"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6454" version="7" class="vulnerability">
      <metadata>
        <title>Data Stream Header Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1547" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1547"/>
        <description>Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via a crafted data stream header that triggers memory corruption, aka "Data Stream Header Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-13T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-10-22T17:36:41.682-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:01:01.776-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:44.288-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6454 - Modified GDR/LDR service branch format to read easier, removed duplicate, and updated extended def for Vista." date="2011-01-31T14:29:00.456-05:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-01-31T14:30:15.951-05:00">INTERIM</status_change>
            <status_change date="2011-02-21T04:01:10.363-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:25:06.602-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:17.460-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6454 - extended definitions of OS are without SP checks" date="2014-07-28T17:42:00.658-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:44:54.783-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:13.860-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 5.01 on Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="Mshtml.dll version is less than 5.0.3881.100" test_ref="oval:org.mitre.oval:tst:10988"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1638" test_ref="oval:org.mitre.oval:tst:10604"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on Windows XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3627" test_ref="oval:org.mitre.oval:tst:10771"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on Windows XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5880" test_ref="oval:org.mitre.oval:tst:10838"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on all Windows XP x64, Server 2003 x86,x64,ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4589" test_ref="oval:org.mitre.oval:tst:10917"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows XP x86, x64">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16915" test_ref="oval:org.mitre.oval:tst:10949"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.21115" test_ref="oval:org.mitre.oval:tst:10971"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16915" test_ref="oval:org.mitre.oval:tst:10949"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.21115" test_ref="oval:org.mitre.oval:tst:10971"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16916" test_ref="oval:org.mitre.oval:tst:10612"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.21116" test_ref="oval:org.mitre.oval:tst:10668"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows Vista x86/x64, all Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6001.18319" test_ref="oval:org.mitre.oval:tst:10928"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6001.22508" test_ref="oval:org.mitre.oval:tst:10959"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows Vista x86/x64, Server 2008 x86/64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6002.18100" test_ref="oval:org.mitre.oval:tst:10793"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6002.22212" test_ref="oval:org.mitre.oval:tst:10952"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6451" version="6" class="vulnerability">
      <metadata>
        <title>Microsoft .NET Framework Type Verification Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft .NET Framework</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0091" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0091"/>
        <description>Microsoft .NET Framework 2.0, 2.0 SP1, and 3.5 does not properly enforce a certain type-equality constraint in .NET verifiable code, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Microsoft .NET Framework Type Verification Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-13T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-10-22T17:36:55.796-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:01:00.874-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:43.442-05:00">ACCEPTED</status_change>
            <modified comment="Updated to reference obj:2009" date="2009-12-01T17:59:00.669-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2009-12-01T18:00:43.811-05:00">INTERIM</status_change>
            <status_change date="2009-12-21T04:00:59.410-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6451 - Updated defs for MS09-061 - updated criteria and modified the GDR/LDR format." date="2011-01-31T17:30:00.645-05:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-01-31T17:33:04.858-05:00">INTERIM</status_change>
            <status_change date="2011-02-21T04:01:09.626-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6451 - extended definitions of OS are without SP checks" date="2014-07-28T17:42:00.658-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:44:55.974-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:13.660-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment=".NET Framework 2.0 on Windows Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 (Original RTM or later) is installed" definition_ref="oval:org.mitre.oval:def:1934"/>
          <criterion comment="the version of Mscorlib.dll is less than 2.0.50727.1003" test_ref="oval:org.mitre.oval:tst:21588"/>
        </criteria>
        <criteria operator="AND" comment=".NET Framework 2.0 SP1">
          <criteria operator="OR" comment="OS section">
            <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:6428"/>
          <criterion comment="the version of Mscorlib.dll is less than 2.0.50727.1873" test_ref="oval:org.mitre.oval:tst:10790"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6437" version="1" class="vulnerability">
      <metadata>
        <title>Maxthon Browser Address Bar Spoofing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Maxthon Browser</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3006" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3006"/>
        <description>Maxthon Browser 2.5.3.80 UNICODE allows remote attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary URL on the web site visited by the victim, as demonstrated by a visit to an attacker-controlled web page, which triggers a spoofed login form for the site containing that page.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-23T10:27:31.430-04:00">
              <contributor organization="SecPod Technologies">Sharath S</contributor>
            </submitted>
            <status_change date="2009-11-23T14:56:41.097-05:00">DRAFT</status_change>
            <status_change date="2009-12-14T04:00:10.939-05:00">INTERIM</status_change>
            <status_change date="2010-01-04T04:01:46.519-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Maxthon Browser is installed" definition_ref="oval:org.mitre.oval:def:6262"/>
        <criterion comment="Maxthon Browser version is equal to 2.5.8.0" test_ref="oval:org.mitre.oval:tst:10908"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6262" version="1" class="inventory">
      <metadata>
        <title>Maxthon Browser is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Maxthon Browser</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:maxthon:maxthon_browser:"/>
        <description>The operating system having Maxthon Browser installation.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-23T10:27:37">
              <contributor organization="SecPod Technologies">Sharath S</contributor>
            </submitted>
            <status_change date="2009-11-23T14:56:40.656-05:00">DRAFT</status_change>
            <status_change date="2009-12-14T04:00:08.792-05:00">INTERIM</status_change>
            <status_change date="2010-01-04T04:01:44.795-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
        </criteria>
        <criterion comment="Maxthon Browser is installed" test_ref="oval:org.mitre.oval:tst:11008"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6430" version="4" class="vulnerability">
      <metadata>
        <title>Office BMP Integer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Office XP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2518" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2518"/>
        <description>Integer overflow in GDI+ in Microsoft Office XP SP3 allows remote attackers to execute arbitrary code via an Office document with a bitmap (aka BMP) image that triggers memory corruption, aka "Office BMP Integer Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-13T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-10-22T17:37:21.332-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:59.154-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:43.170-05:00">ACCEPTED</status_change>
            <modified comment="Changed product &quot;Office 2002&quot; to &quot;Office XP&quot;" date="2010-01-14T15:36:00.885-05:00">
              <contributor organization="The MITRE Corporation">Mike Lah</contributor>
            </modified>
            <status_change date="2010-01-14T15:37:16.891-05:00">INTERIM</status_change>
            <status_change date="2010-02-01T04:00:24.818-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6430 - Fixed several false positives by setting negate = true.  Also fixed several style issues." date="2011-12-28T21:13:00.551-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2011-12-28T21:20:58.464-05:00">INTERIM</status_change>
            <status_change date="2012-01-16T04:03:16.739-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Vulnerable Microsoft Office XP, Project 2002, Visio 2002">
          <extend_definition comment="Microsoft Office XP is installed" definition_ref="oval:org.mitre.oval:def:663"/>
          <extend_definition comment="Microsoft Project 2002 SP1 is installed" definition_ref="oval:org.mitre.oval:def:707"/>
          <extend_definition comment="Microsoft Office Visio 2002 SP2 is installed" definition_ref="oval:org.mitre.oval:def:692"/>
        </criteria>
        <criterion comment="Mso.dll version is less than 10.0.6856.0" test_ref="oval:org.mitre.oval:tst:10932"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:643" version="5" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP3 Travel Log Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1026" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1026"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:50:00.000-04:00" comment="modified wft-90 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2824. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:48:00.494-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:52:26.933-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:50.618-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:44.138-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:24.990-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3015"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3526.800" negate="false" test_ref="oval:org.mitre.oval:tst:2589"/>
          <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6426" version="4" class="vulnerability">
      <metadata>
        <title>Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Office XP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2528" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2528"/>
        <description>GDI+ in Microsoft Office XP SP3 does not properly handle malformed objects in Office Art Property Tables, which allows remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption, aka "Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-13T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-10-22T17:37:21.158-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:57.700-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:42.161-05:00">ACCEPTED</status_change>
            <modified comment="Changed product &quot;Office 2002&quot; to &quot;Office XP&quot;" date="2010-01-14T15:37:00.456-05:00">
              <contributor organization="The MITRE Corporation">Mike Lah</contributor>
            </modified>
            <status_change date="2010-01-14T15:37:39.462-05:00">INTERIM</status_change>
            <status_change date="2010-02-01T04:00:24.525-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6426 - Fixed several false positives by setting negate = true.  Also fixed several style issues." date="2011-12-28T21:13:00.551-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2011-12-28T21:21:11.278-05:00">INTERIM</status_change>
            <status_change date="2012-01-16T04:03:16.403-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Vulnerable Microsoft Office XP, Project 2002, Visio 2002">
          <extend_definition comment="Microsoft Office XP is installed" definition_ref="oval:org.mitre.oval:def:663"/>
          <extend_definition comment="Microsoft Project 2002 SP1 is installed" definition_ref="oval:org.mitre.oval:def:707"/>
          <extend_definition comment="Microsoft Office Visio 2002 SP2 is installed" definition_ref="oval:org.mitre.oval:def:692"/>
        </criteria>
        <criterion comment="Mso.dll version is less than 10.0.6856.0" test_ref="oval:org.mitre.oval:tst:10932"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:707" version="1" class="inventory">
      <metadata>
        <title>Microsoft Project 2002 SP1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:project:2002:sp1"/>
        <description>The application Microsoft Project 2002 SP1 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-07T09:15:51.895-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:59.024-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Windows Project Professional 2002 Service Pack 1 is installed" test_ref="oval:org.mitre.oval:tst:555"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:692" version="3" class="inventory">
      <metadata>
        <title>Microsoft Office Visio 2002 SP2 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Office Visio 2002</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:visio:2002:sp2"/>
        <description>The application Microsoft Office Visio 2002 SP2 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-07T09:15:51.484-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:58.914-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:692 - products added to inventories" date="2015-04-17T09:41:00.607-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-04-17T09:42:54.947-04:00">INTERIM</status_change>
            <status_change date="2015-05-04T04:00:21.507-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Microsoft Office Visio Professional 2002 with service pack 2" test_ref="oval:org.mitre.oval:tst:481"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6421" version="3" class="vulnerability" deprecated="true">
      <metadata>
        <title>ATL COM Initialization Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2493" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2493"/>
        <description>The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1; and Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2; does not properly restrict use of OleLoadFromStream in instantiating objects from data streams, which allows remote attackers to execute arbitrary code via a crafted HTML document with an ATL (1) component or (2) control, related to ATL headers and bypassing security policies, aka "ATL COM Initialization Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-13T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-10-22T17:37:02.292-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:56.358-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:41.161-05:00">ACCEPTED</status_change>
            <modified comment="Deprecated after consolidating other definitions for the same CVE. The new consolidated definition is oval:org.mitre.oval:def:6716" date="2010-01-03T18:00:11.513-04:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2010-01-03T18:00:11.513-04:00">DEPRECATED</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:45.946-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:ste:3992 - modified vulnerabilities ofÂ MS Visual C++ Â  (winsxs folder checks were modified)" date="2014-04-17T13:09:00.881-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
          <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
          <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
        </criteria>
        <criteria operator="OR">
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0002E531-0000-0000-C000-000000000046}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10568"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0002E531-0000-0000-C000-000000000046}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10739"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{4C85388F-1500-11D1-A0DF-00C04FC9E20F}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10428"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{4C85388F-1500-11D1-A0DF-00C04FC9E20F}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10956"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0002E532-0000-0000-C000-000000000046}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10741"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0002E532-0000-0000-C000-000000000046}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10559"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0002E554-0000-0000-C000-000000000046}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10837"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0002E554-0000-0000-C000-000000000046}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10923"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0002E55C-0000-0000-C000-000000000046}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10592"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0002E55C-0000-0000-C000-000000000046}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10657"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{279D6C9A-652E-4833-BEFC-312CA8887857}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10978"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{279D6C9A-652E-4833-BEFC-312CA8887857}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10876"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{B1F78FEF-3DB7-4C56-AF2B-5DCCC7C42331}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10927"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{B1F78FEF-3DB7-4C56-AF2B-5DCCC7C42331}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10844"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{C832BE8F-4B89-4579-A217-DB92E7A27915}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:11009"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{C832BE8F-4B89-4579-A217-DB92E7A27915}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10968"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{A9A7297E-969C-43F1-A1EF-51EBEA36F850}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10708"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{A9A7297E-969C-43F1-A1EF-51EBEA36F850}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10997"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{DD8C2179-1B4A-4951-B432-5DE3D1507142}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10786"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{DD8C2179-1B4A-4951-B432-5DE3D1507142}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10822"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{4F1E5B1A-2A80-42ca-8532-2D05CB959537}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10892"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{4F1E5B1A-2A80-42ca-8532-2D05CB959537}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10680"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{27A3D328-D206-4106-8D33-1AA39B13394B}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10951"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{27A3D328-D206-4106-8D33-1AA39B13394B}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10887"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{DB640C86-731C-484A-AAAF-750656C9187D}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10198"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{DB640C86-731C-484A-AAAF-750656C9187D}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10986"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{15721a53-8448-4731-8bfc-ed11e128e444}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10698"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{15721a53-8448-4731-8bfc-ed11e128e444}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10823"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{3267123E-530D-4E73-9DA7-79F01D86A89F}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10819"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{3267123E-530D-4E73-9DA7-79F01D86A89F}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10829"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6419" version="7" class="vulnerability">
      <metadata>
        <title>HTML Component Handling Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2529" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2529"/>
        <description>Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not properly handle argument validation for unspecified variables, which allows remote attackers to execute arbitrary code via a crafted HTML document, aka "HTML Component Handling Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-13T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-10-22T17:36:43.021-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:55.156-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:39.889-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6419 - Modified GDR/LDR service branch format to read easier, removed duplicate, and updated extended def for Vista." date="2011-01-31T14:29:00.857-05:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-01-31T14:29:43.057-05:00">INTERIM</status_change>
            <status_change date="2011-02-21T04:01:08.660-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:25:10.546-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:17.089-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6419 - extended definitions of OS are without SP checks" date="2014-07-28T17:42:00.658-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:44:52.016-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:13.435-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 5.01 on Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="Mshtml.dll version is less than 5.0.3881.100" test_ref="oval:org.mitre.oval:tst:10988"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1638" test_ref="oval:org.mitre.oval:tst:10604"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on Windows XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3627" test_ref="oval:org.mitre.oval:tst:10771"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on Windows XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5880" test_ref="oval:org.mitre.oval:tst:10838"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on all Windows XP x64, Server 2003 x86,x64,ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4589" test_ref="oval:org.mitre.oval:tst:10917"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows XP x86, x64">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16915" test_ref="oval:org.mitre.oval:tst:10949"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.21115" test_ref="oval:org.mitre.oval:tst:10971"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16915" test_ref="oval:org.mitre.oval:tst:10949"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.21115" test_ref="oval:org.mitre.oval:tst:10971"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16916" test_ref="oval:org.mitre.oval:tst:10612"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.21116" test_ref="oval:org.mitre.oval:tst:10668"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows Vista x86/x64, all Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6001.18319" test_ref="oval:org.mitre.oval:tst:10928"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6001.22508" test_ref="oval:org.mitre.oval:tst:10959"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows Vista x86/x64, Server 2008 x86/64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6002.18100" test_ref="oval:org.mitre.oval:tst:10793"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6002.22212" test_ref="oval:org.mitre.oval:tst:10952"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Windows XP x86, x64, Server 2003 x86/x64 , Vista x86/x64, x86 SP2, Server 2008 x86/x64, x86/x64 SP2">
          <criteria operator="OR" comment="OS section">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 8.0.6001.18828" test_ref="oval:org.mitre.oval:tst:10824"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
              <criterion comment="Mshtml.dll version is less than 8.0.6001.22918" test_ref="oval:org.mitre.oval:tst:10966"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6410" version="1" class="vulnerability">
      <metadata>
        <title>WINS Heap Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1923" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1923"/>
        <description>Heap-based buffer overflow in the Windows Internet Name Service (WINS) component for Microsoft Windows 2000 SP4 and Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted WINS replication packet that triggers an incorrect buffer-length calculation, aka "WINS Heap Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-07-28T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-08-19T14:57:55.730-04:00">DRAFT</status_change>
            <status_change date="2009-09-07T04:00:20.447-04:00">INTERIM</status_change>
            <status_change date="2009-09-28T04:00:28.690-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Microsoft Windows 2000 SP4 is vulnerable">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of wins.exe is less than 5.0.2195.7300" test_ref="oval:org.mitre.oval:tst:10480"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <criterion comment="the version of wins.exe is less than 5.2.3790.4520" test_ref="oval:org.mitre.oval:tst:10341"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
          <criterion comment="the version of wins.exe is less than 5.2.3790.4520" test_ref="oval:org.mitre.oval:tst:10341"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          <criterion comment="the version of wins.exe is less than 5.2.3790.4520" test_ref="oval:org.mitre.oval:tst:10341"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6406" version="1" class="vulnerability">
      <metadata>
        <title>Win32k EOT Parsing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2514" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2514"/>
        <description>win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not correctly parse font code during construction of a directory-entry table, which allows remote attackers to execute arbitrary code via a crafted Embedded OpenType (EOT) font, aka "Win32k EOT Parsing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-10T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-11-12T15:32:30.799-05:00">DRAFT</status_change>
            <status_change date="2009-11-30T04:00:37.504-05:00">INTERIM</status_change>
            <status_change date="2009-12-21T04:00:57.460-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of win32k.sys is less than 5.0.2195.7322" test_ref="oval:org.mitre.oval:tst:11065"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="the version of win32k.sys is less than 5.1.2600.3614" test_ref="oval:org.mitre.oval:tst:10898"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of win32k.sys is less than 5.1.2600.5863" test_ref="oval:org.mitre.oval:tst:11060"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of win32k.sys is less than 5.2.3790.4571" test_ref="oval:org.mitre.oval:tst:10856"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:64" version="3" class="vulnerability">
      <metadata>
        <title>Windows 2000 Trusted Domain Loophole</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0018" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0018"/>
        <description>In Microsoft Windows NT and Windows 2000, a trusting domain that receives authorization information from a trusted domain does not verify that the trusted domain is authoritative for all listed SIDs, which allows remote attackers to gain Domain Administrator privileges on the trusting domain by injecting SIDs from untrusted domains into the authorization data that comes from from the trusted domain.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-05-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2004-08-04T12:00:00.000-04:00" comment="Modifed without comment">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </modified>
            <status_change date="2004-08-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2004-08-26T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T10:56:00.000-04:00" comment="modified wft-220 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="File %windir%\system32\netlogon.dll version is less than 5.0.893.1105" negate="false" test_ref="oval:org.mitre.oval:tst:2991"/>
        <criterion comment="Windows 2000 Security Roll-up 1 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2990"/>
        <criterion comment="Patch Q319733 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3095"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6381" version="5" class="vulnerability">
      <metadata>
        <title>HTML Object Memory Corruption Vulnerability (CVE-2009-3672)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3672" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3672"/>
        <description>Microsoft Internet Explorer 6 and 7 does not properly handle objects in memory that (1) were not properly initialized or (2) are deleted, which allows remote attackers to execute arbitrary code via vectors involving a call to the getElementsByTagName method for the STYLE tag name, selection of the single element in the returned list, and a change to the outerHTML property of this element, related to Cascading Style Sheets (CSS) and mshtml.dll, aka "HTML Object Memory Corruption Vulnerability." NOTE: some of these details are obtained from third party information. NOTE: this issue was originally assigned CVE-2009-4054, but Microsoft assigned a duplicate identifier of CVE-2009-3672. CVE consumers should use this identifier instead of CVE-2009-4054.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-08T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-12-11T11:36:10.570-05:00">DRAFT</status_change>
            <status_change date="2009-12-28T04:00:31.214-05:00">INTERIM</status_change>
            <status_change date="2010-01-18T04:00:06.730-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:25:02.728-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:16.876-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6381 - extended definitions of OS are without SP checks" date="2014-07-28T17:41:00.906-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:42:53.318-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:12.393-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE6/Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1642" test_ref="oval:org.mitre.oval:tst:10363"/>
        </criteria>
        <criteria operator="AND" comment="IE6/XP (32-bit)">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3640" test_ref="oval:org.mitre.oval:tst:11188"/>
        </criteria>
        <criteria operator="AND" comment="IE6/XP (32-bit)">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5897" test_ref="oval:org.mitre.oval:tst:11032"/>
        </criteria>
        <criteria operator="AND" comment="IE6/XP x64/server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4611" test_ref="oval:org.mitre.oval:tst:11149"/>
        </criteria>
        <criteria operator="AND" comment="IE7/XP x86/x64">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16945" test_ref="oval:org.mitre.oval:tst:10323"/>
        </criteria>
        <criteria operator="AND" comment="IE7/XP x86/x64">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21148" test_ref="oval:org.mitre.oval:tst:11055"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16945" test_ref="oval:org.mitre.oval:tst:10323"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21148" test_ref="oval:org.mitre.oval:tst:11055"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16945" test_ref="oval:org.mitre.oval:tst:10323"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21148" test_ref="oval:org.mitre.oval:tst:11055"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.16000" test_ref="oval:org.mitre.oval:tst:9444"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.18349" test_ref="oval:org.mitre.oval:tst:10560"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.22550" test_ref="oval:org.mitre.oval:tst:11161"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.18000" test_ref="oval:org.mitre.oval:tst:10094"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.18130" test_ref="oval:org.mitre.oval:tst:11275"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6002.22252" test_ref="oval:org.mitre.oval:tst:11036"/>
        </criteria>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:638" version="1">
      <metadata>
        <title>MMC Redirect Cross-Site Scripting Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Management Console</product>
        </affected>
        <reference ref_id="CVE-2006-3643" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3643" source="CVE"/>
        <description>Cross-site scripting (XSS) vulnerability in Internet Explorer 5.01 and 6 in Microsoft Windows 2000 SP4 permits access to local "HTML-embedded resource files" in the Microsoft Management Console (MMC) library, which allows remote authenticated users to execute arbitrary commands, aka "MMC Redirect Cross-Site Scripting Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:32.866-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:45.812-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
        <criterion comment="the version of mmc.exe is less than 5.0.2195.7102" test_ref="oval:org.mitre.oval:tst:193"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6354" version="1" class="vulnerability">
      <metadata>
        <title>WINS Integer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1924" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1924"/>
        <description>Integer overflow in the Windows Internet Name Service (WINS) component for Microsoft Windows 2000 SP4 allows remote WINS replication partners to execute arbitrary code via crafted data structures in a packet, aka "WINS Integer Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-07-28T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-08-19T14:57:55.927-04:00">DRAFT</status_change>
            <status_change date="2009-09-07T04:00:18.694-04:00">INTERIM</status_change>
            <status_change date="2009-09-28T04:00:25.942-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
        <criterion comment="the version of wins.exe is less than 5.0.2195.7300" test_ref="oval:org.mitre.oval:tst:10480"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6341" version="3" class="vulnerability">
      <metadata>
        <title>DirectX Size Validation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>DirectX</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1539" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1539"/>
        <description>The QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2 does not properly validate unspecified size fields in QuickTime media files, which allows remote attackers to execute arbitrary code via a crafted file, aka "DirectX Size Validation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-07-14T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-07-20T15:51:20.201-04:00">DRAFT</status_change>
            <status_change date="2009-08-10T04:00:10.559-04:00">INTERIM</status_change>
            <status_change date="2009-08-31T04:00:13.515-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:3502 - obj/ste updates to conform to authoring style guide" date="2013-03-26T09:53:00.500-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-03-26T09:55:55.631-04:00">INTERIM</status_change>
            <status_change date="2013-04-15T04:00:29.362-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="DirectX 7 on Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="DirectX 7.0x Installed" test_ref="oval:org.mitre.oval:tst:1296"/>
          <criterion comment="the version of Quartz.dll is less than 6.1.9.736" test_ref="oval:org.mitre.oval:tst:10181"/>
        </criteria>
        <criteria operator="AND" comment="DirectX 8.1 on Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="DirectX 8.1 Installed" test_ref="oval:org.mitre.oval:tst:6805"/>
          <criterion comment="the version of Quartz.dll is less than 6.3.1.893" test_ref="oval:org.mitre.oval:tst:10229"/>
        </criteria>
        <criteria operator="AND" comment="DirectX 9.0 on Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="DirectX 9.0x Installed" test_ref="oval:org.mitre.oval:tst:601"/>
          <criterion comment="the version of Quartz.dll is less than 6.5.1.911" test_ref="oval:org.mitre.oval:tst:10131"/>
        </criteria>
        <criteria operator="AND" comment="DirectX 9.0 on Win XP SP2 x86">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="DirectX 9.0x Installed" test_ref="oval:org.mitre.oval:tst:601"/>
          <criterion comment="the version of Quartz.dll is less than 6.5.2600.3580" test_ref="oval:org.mitre.oval:tst:10177"/>
        </criteria>
        <criteria operator="AND" comment="DirectX 9.0 on Win XP SP3 x86">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="DirectX 9.0x Installed" test_ref="oval:org.mitre.oval:tst:601"/>
          <criterion comment="the version of Quartz.dll is less than 6.5.2600.5822" test_ref="oval:org.mitre.oval:tst:10081"/>
        </criteria>
        <criteria operator="AND" comment="DirectX 9.0 on Windows XP SP2, Server 2003 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="DirectX 9.0x Installed" test_ref="oval:org.mitre.oval:tst:601"/>
          <criterion comment="the version of Quartz.dll is less than 6.5.3790.4523" test_ref="oval:org.mitre.oval:tst:10047"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6340" version="1" class="vulnerability">
      <metadata>
        <title>TCP/IP Zero Window Size Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4609" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4609"/>
        <description>The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cisco products, and probably other operating systems allows remote attackers to cause a denial of service (connection queue exhaustion) via multiple vectors that manipulate information in the TCP state table, as demonstrated by sockstress.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-08T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-09-12T20:28:16.956-04:00">DRAFT</status_change>
            <status_change date="2009-09-28T04:00:24.963-04:00">INTERIM</status_change>
            <status_change date="2009-10-19T04:00:15.637-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
        </criteria>
        <criteria operator="OR" comment="Windows XP SP2/SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
        </criteria>
        <criteria operator="AND" comment="Windows Server 2003 X86/X64/IA64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criteria operator="OR">
            <criterion comment="the version of Tcpip.sys is less than 5.2.3790.4573" test_ref="oval:org.mitre.oval:tst:10768"/>
            <criterion comment="The version of Tcpip6.sys is less than 5.2.3790.4573" test_ref="oval:org.mitre.oval:tst:10446"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="The version of Tcpip.sys is less than 6.0.6000.16908" test_ref="oval:org.mitre.oval:tst:9931"/>
          <criterion comment="the version of Tcpip.sys is greater than or equal 6.0.6000.16000" test_ref="oval:org.mitre.oval:tst:10605"/>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64 SP1, Windows Server 2008 x86/x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="The version of Tcpip.sys is less than 6.0.6001.18311" test_ref="oval:org.mitre.oval:tst:10280"/>
          <criterion comment="the version of Tcpip.sys is greater than or equal 6.0.6001.18000" test_ref="oval:org.mitre.oval:tst:10548"/>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64 SP2, Windows Server 2008 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="The version of Tcpip.sys is less than 6.0.6002.18091" test_ref="oval:org.mitre.oval:tst:10600"/>
          <criterion comment="the version of Tcpip.sys is greater than or equal 6.0.6002.18000" test_ref="oval:org.mitre.oval:tst:10640"/>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="The version of Tcpip.sys is less than 6.0.6000.21108" test_ref="oval:org.mitre.oval:tst:10773"/>
          <criterion comment="the version of Tcpip.sys is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:10454"/>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64 SP1, Windows Server 2008 x86/x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="The version of Tcpip.sys is less than 6.0.6001.22497" test_ref="oval:org.mitre.oval:tst:10806"/>
          <criterion comment="the version of Tcpip.sys is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:10695"/>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64 SP2, Windows Server 2008 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="The version of Tcpip.sys is less than 6.0.6002.22200" test_ref="oval:org.mitre.oval:tst:9812"/>
          <criterion comment="the version of Tcpip.sys is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10619"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6333" version="3" class="vulnerability" deprecated="true">
      <metadata>
        <title>Microsoft Video ActiveX Control Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0015" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0015"/>
        <description>Stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL), as used in the MPEG2TuneRequest ActiveX control in msvidctl.dll in DirectShow, in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted web page, as exploited in the wild in July 2009, aka "Microsoft Video ActiveX Control Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-07-14T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-07-20T15:51:32.502-04:00">DRAFT</status_change>
            <status_change date="2009-08-10T04:00:09.009-04:00">INTERIM</status_change>
            <status_change date="2009-08-31T04:00:11.829-04:00">ACCEPTED</status_change>
            <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:54:00.233-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <status_change date="2009-12-04T14:55:07.669-05:00">INTERIM</status_change>
            <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:55:00.401-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <modified comment="Updated regex to allow parenthesis" date="2009-12-08T15:29:00.543-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <modified comment="Updating regex to include parenthesis" date="2009-12-08T17:31:00.669-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <status_change date="2009-12-28T04:00:28.579-05:00">ACCEPTED</status_change>
            <modified comment="Deprecated after consolidating other definitions for the same CVE. The new consolidated definition is oval:org.mitre.oval:def:7436" date="2010-01-03T18:00:11.513-04:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2010-01-03T18:00:11.513-04:00">DEPRECATED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:3992 - modified vulnerabilities ofÂ MS Visual C++ Â  (winsxs folder checks were modified)" date="2014-04-17T13:09:00.881-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          <criterion comment="Windows Vista is installed" test_ref="oval:org.mitre.oval:tst:7914"/>
          <criterion comment="Windows Server 2008 is installed" test_ref="oval:org.mitre.oval:tst:7697"/>
        </criteria>
        <criteria operator="OR">
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{011B3619-FE63-4814-8A84-15A194CE9CE3}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10237"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{011B3619-FE63-4814-8A84-15A194CE9CE3}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:9959"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0149EEDF-D08F-4142-8D73-D23903D21E90}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10290"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0149EEDF-D08F-4142-8D73-D23903D21E90}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10111"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0369B4E5-45B6-11D3-B650-00C04F79498E}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10188"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0369B4E5-45B6-11D3-B650-00C04F79498E}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10239"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0369B4E6-45B6-11D3-B650-00C04F79498E}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10123"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0369B4E6-45B6-11D3-B650-00C04F79498E}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10279"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{055CB2D7-2969-45CD-914B-76890722F112}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:9973"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{055CB2D7-2969-45CD-914B-76890722F112}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:9926"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0955AC62-BF2E-4CBA-A2B9-A63F772D46CF}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:9890"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0955AC62-BF2E-4CBA-A2B9-A63F772D46CF}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:9993"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{15D6504A-5494-499C-886C-973C9E53B9F1}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:9889"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{15D6504A-5494-499C-886C-973C9E53B9F1}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10272"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{1BE49F30-0E1B-11D3-9D8E-00C04F72D980}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:9645"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{1BE49F30-0E1B-11D3-9D8E-00C04F72D980}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10085"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{1C15D484-911D-11D2-B632-00C04F79498E}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:9943"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{1C15D484-911D-11D2-B632-00C04F79498E}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:9995"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{1DF7D126-4050-47F0-A7CF-4C4CA9241333}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10267"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{1DF7D126-4050-47F0-A7CF-4C4CA9241333}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:9894"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{2C63E4EB-4CEA-41B8-919C-E947EA19A77C}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:9548"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{2C63E4EB-4CEA-41B8-919C-E947EA19A77C}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10281"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{334125C0-77E5-11D3-B653-00C04F79498E}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10121"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{334125C0-77E5-11D3-B653-00C04F79498E}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10289"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{37B0353C-A4C8-11D2-B634-00C04F79498E}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:9996"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{37B0353C-A4C8-11D2-B634-00C04F79498E}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10286"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{37B03543-A4C8-11D2-B634-00C04F79498E}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:9860"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{37B03543-A4C8-11D2-B634-00C04F79498E}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:9917"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{37B03544-A4C8-11D2-B634-00C04F79498E}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10169"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{37B03544-A4C8-11D2-B634-00C04F79498E}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10119"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{418008F3-CF67-4668-9628-10DC52BE1D08}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10313"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{418008F3-CF67-4668-9628-10DC52BE1D08}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:9954"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{4A5869CF-929D-4040-AE03-FCAFC5B9CD42}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10295"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{4A5869CF-929D-4040-AE03-FCAFC5B9CD42}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10037"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{577FAA18-4518-445E-8F70-1473F8CF4BA4}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10184"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{577FAA18-4518-445E-8F70-1473F8CF4BA4}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10017"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{59DC47A8-116C-11D3-9D8E-00C04F72D980}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10178"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{59DC47A8-116C-11D3-9D8E-00C04F72D980}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10303"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{7F9CB14D-48E4-43B6-9346-1AEBC39C64D3}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10196"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{7F9CB14D-48E4-43B6-9346-1AEBC39C64D3}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10245"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{823535A0-0318-11D3-9D8E-00C04F72D980}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:9424"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{823535A0-0318-11D3-9D8E-00C04F72D980}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10044"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{8872FF1B-98FA-4D7A-8D93-C9F1055F85BB}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10336"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{8872FF1B-98FA-4D7A-8D93-C9F1055F85BB}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10414"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{8A674B4C-1F63-11D3-B64C-00C04F79498E}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10416"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{8A674B4C-1F63-11D3-B64C-00C04F79498E}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:9852"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{8A674B4D-1F63-11D3-B64C-00C04F79498E}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10415"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{8A674B4D-1F63-11D3-B64C-00C04F79498E}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10257"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{9CD64701-BDF3-4D14-8E03-F12983D86664}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:9957"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{9CD64701-BDF3-4D14-8E03-F12983D86664}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10369"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{9E77AAC4-35E5-42A1-BDC2-8F3FF399847C}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:9967"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{9E77AAC4-35E5-42A1-BDC2-8F3FF399847C}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10349"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{A1A2B1C4-0E3A-11D3-9D8E-00C04F72D980}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10311"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{A1A2B1C4-0E3A-11D3-9D8E-00C04F72D980}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10314"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{A2E3074E-6C3D-11D3-B653-00C04F79498E}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10345"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{A2E3074E-6C3D-11D3-B653-00C04F79498E}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10370"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{A2E30750-6C3D-11D3-B653-00C04F79498E}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10400"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{A2E30750-6C3D-11D3-B653-00C04F79498E}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10274"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{A8DCF3D5-0780-4EF4-8A83-2CFFAACB8ACE}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10203"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{A8DCF3D5-0780-4EF4-8A83-2CFFAACB8ACE}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10165"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{AD8E510D-217F-409B-8076-29C5E73B98E8}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10372"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{AD8E510D-217F-409B-8076-29C5E73B98E8}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:9876"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{B0EDF163-910A-11D2-B632-00C04F79498E}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:9975"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{B0EDF163-910A-11D2-B632-00C04F79498E}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10389"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{B64016F3-C9A2-4066-96F0-BD9563314726}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10155"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{B64016F3-C9A2-4066-96F0-BD9563314726}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10059"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{BB530C63-D9DF-4B49-9439-63453962E598}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10191"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{BB530C63-D9DF-4B49-9439-63453962E598}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:9885"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{C531D9FD-9685-4028-8B68-6E1232079F1E}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10186"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{C531D9FD-9685-4028-8B68-6E1232079F1E}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10271"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{C5702CCC-9B79-11D3-B654-00C04F79498E}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10420"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{C5702CCC-9B79-11D3-B654-00C04F79498E}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10269"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{C5702CCD-9B79-11D3-B654-00C04F79498E}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10064"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{C5702CCD-9B79-11D3-B654-00C04F79498E}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10153"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{C5702CCE-9B79-11D3-B654-00C04F79498E}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10170"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{C5702CCE-9B79-11D3-B654-00C04F79498E}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:9848"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{C5702CCF-9B79-11D3-B654-00C04F79498E}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10135"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{C5702CCF-9B79-11D3-B654-00C04F79498E}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10379"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{C5702CD0-9B79-11D3-B654-00C04F79498E}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10326"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{C5702CD0-9B79-11D3-B654-00C04F79498E}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10224"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{C6B14B32-76AA-4A86-A7AC-5C79AAF58DA7}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10371"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{C6B14B32-76AA-4A86-A7AC-5C79AAF58DA7}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:9835"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{CAAFDD83-CEFC-4E3D-BA03-175F17A24F91}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10175"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{CAAFDD83-CEFC-4E3D-BA03-175F17A24F91}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10293"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{D02AAC50-027E-11D3-9D8E-00C04F72D980}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10333"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{D02AAC50-027E-11D3-9D8E-00C04F72D980}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10340"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{F9769A06-7ACA-4E39-9CFB-97BB35F0E77E}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:9782"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{F9769A06-7ACA-4E39-9CFB-97BB35F0E77E}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10199"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{FA7C375B-66A7-4280-879D-FD459C84BB02}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:10319"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{FA7C375B-66A7-4280-879D-FD459C84BB02}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:10344"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6317" version="1" class="vulnerability">
      <metadata>
        <title>Buffer Overflow in Print Spooler Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0228" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0228"/>
        <description>Stack-based buffer overflow in the EnumeratePrintShares function in Windows Print Spooler Service (win32spl.dll) in Microsoft Windows 2000 SP4 allows remote printer servers to execute arbitrary code via a a crafted ShareName in a response to an RPC request, related to "printing data structures," aka "Buffer Overflow in Print Spooler Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-06-09T14:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-06-15T17:07:09.694-04:00">DRAFT</status_change>
            <status_change date="2009-07-06T04:00:57.957-04:00">INTERIM</status_change>
            <status_change date="2009-07-21T07:46:10.235-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
        <criterion comment="Win32spl.dll version is less than 5.0.2195.7266" test_ref="oval:org.mitre.oval:tst:9847"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6308" version="7" class="vulnerability">
      <metadata>
        <title>HTML Object Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1531" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1531"/>
        <description>Microsoft Internet Explorer 7 for Windows XP SP2 and SP3; 7 for Server 2003 SP2; 7 for Vista Gold, SP1, and SP2; and 7 for Server 2008 SP2 allows remote attackers to execute arbitrary code via frequent calls to the getElementsByTagName function combined with the creation of an object during reordering of elements, followed by an onreadystatechange event, which triggers an access of an object that (1) was not properly initialized or (2) is deleted, aka "HTML Object Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-06-09T14:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-06-15T17:06:47.402-04:00">DRAFT</status_change>
            <modified comment="Updated title" date="2009-06-16T10:32:00.713-04:00">
              <contributor organization="The MITRE Corporation">Brendan Miles</contributor>
            </modified>
            <status_change date="2009-07-06T04:00:56.608-04:00">INTERIM</status_change>
            <status_change date="2009-07-21T07:46:09.561-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6308 - Modified GDR/LDR service branch format to read easier, removed duplicate, and updated extended def for Vista." date="2011-01-31T14:28:00.100-05:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-01-31T14:29:08.420-05:00">INTERIM</status_change>
            <status_change date="2011-02-21T04:01:07.878-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:25:05.291-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:16.663-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6308 - extended definitions of OS are without SP checks" date="2014-07-28T17:41:00.906-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:42:49.922-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:11.647-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows XP x86, x64">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16850" test_ref="oval:org.mitre.oval:tst:10212"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.21045" test_ref="oval:org.mitre.oval:tst:10207"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16850" test_ref="oval:org.mitre.oval:tst:10212"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.21045" test_ref="oval:org.mitre.oval:tst:10207"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16851" test_ref="oval:org.mitre.oval:tst:9914"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.21046" test_ref="oval:org.mitre.oval:tst:10068"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows Vista x86/x64, all Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6001.18248" test_ref="oval:org.mitre.oval:tst:9929"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6001.22418" test_ref="oval:org.mitre.oval:tst:9978"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows Vista x86/x64, Server 2008 x86/64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6002.18024" test_ref="oval:org.mitre.oval:tst:9840"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6002.22121" test_ref="oval:org.mitre.oval:tst:10061"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6302" version="1" class="vulnerability">
      <metadata>
        <title>Telnet Credential Reflection Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1930" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1930"/>
        <description>The Telnet service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote Telnet servers to execute arbitrary code on a client machine by replaying the NTLM credentials of a client user, aka "Telnet Credential Reflection Vulnerability," a related issue to CVE-2000-0834.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-07-28T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-08-19T14:58:03.968-04:00">DRAFT</status_change>
            <status_change date="2009-09-07T04:00:16.275-04:00">INTERIM</status_change>
            <status_change date="2009-09-28T04:00:21.810-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of telnet.exe is less than 5.0.33670.4" test_ref="oval:org.mitre.oval:tst:10488"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="the version of telnet.exe is less than 5.1.2600.3587" test_ref="oval:org.mitre.oval:tst:10643"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of telnet.exe is less than 5.1.2600.5829" test_ref="oval:org.mitre.oval:tst:10644"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of telnet.exe is less than 5.2.3790.4528" test_ref="oval:org.mitre.oval:tst:10578"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="the version of telnet.exe is less than 6.0.6000.16868" test_ref="oval:org.mitre.oval:tst:10631"/>
          <criterion comment="the version of telnet.exe is greater than or equal 6.0.6000.16000" test_ref="oval:org.mitre.oval:tst:10354"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="the version of telnet.exe is less than 6.0.6000.21065" test_ref="oval:org.mitre.oval:tst:10636"/>
          <criterion comment="the version of telnet.exe is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:10607"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of telnet.exe is less than 6.0.6001.18270" test_ref="oval:org.mitre.oval:tst:10545"/>
          <criterion comment="the version of telnet.exe is greater than or equal 6.0.6001.18000" test_ref="oval:org.mitre.oval:tst:10310"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of telnet.exe is less than 6.0.6001.22447" test_ref="oval:org.mitre.oval:tst:9882"/>
          <criterion comment="the version of telnet.exe is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:10618"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="the version of telnet.exe is less than 6.0.6002.18049" test_ref="oval:org.mitre.oval:tst:10076"/>
          <criterion comment="the version of wkssvc.dll is greater than or equal 6.0.6002.18000" test_ref="oval:org.mitre.oval:tst:10620"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="the version of telnet.exe is less than 6.0.6002.22150" test_ref="oval:org.mitre.oval:tst:10422"/>
          <criterion comment="the version of wkssvc.dll is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10544"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6300" version="1" class="vulnerability">
      <metadata>
        <title>License Logging Server Heap Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>SMBv2</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2523" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2523"/>
        <description>The License Logging Server (llssrv.exe) in Microsoft Windows 2000 SP4 allows remote attackers to execute arbitrary code via an RPC message containing a string without a null terminator, which triggers a heap-based buffer overflow in the LlsrLicenseRequestW method, aka "License Logging Server Heap Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-10T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-11-12T15:32:25.388-05:00">DRAFT</status_change>
            <status_change date="2009-11-30T04:00:32.708-05:00">INTERIM</status_change>
            <modified comment="Updated comments" date="2009-12-08T15:23:00.250-05:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2009-12-28T04:00:26.884-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
        <criterion comment="The version of Llssrv.exe is less than 5.0.2195.7337" test_ref="oval:org.mitre.oval:tst:11037"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:630" version="5" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP2 Travel Log Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1026" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1026"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:50:00.000-04:00" comment="modified wft-90 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2868. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:41:00.387-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:43:10.741-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:50.053-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:48.729-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:24.834-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3063"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3526.800" negate="false" test_ref="oval:org.mitre.oval:tst:2589"/>
          <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:63" version="6" class="vulnerability">
      <metadata>
        <title>Windows 2000 Remote Access Service Phonebook Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Remote Access Service (RAS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0366" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0366"/>
        <description>Buffer overflow in Remote Access Service (RAS) phonebook for Windows NT 4.0, 2000, XP, and Routing and Remote Access Server (RRAS) allows local users to execute arbitrary code by modifying the rasphone.pbk file to use a long dial-up entry.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-04-04T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified comment="Multiple corrections and update to POSIX compatibility for ste:2884" date="2010-11-29T16:14:00.692-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-11-29T16:14:40.053-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:01:04.202-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:27.244-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:03:18.751-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="RAS Phonebook" negate="false" test_ref="oval:org.mitre.oval:tst:2999"/>
          <criterion comment="File %windir%\system32\rasman.dll version is less than 5.0.2195.4983" negate="false" test_ref="oval:org.mitre.oval:tst:2992"/>
          <criterion comment="Patch Q318138 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2997"/>
          <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3079"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="RAS Enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2996"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6295" version="7" class="vulnerability">
      <metadata>
        <title>Uninitialized Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1529" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1529"/>
        <description>Microsoft Internet Explorer 7 for Windows XP SP2 and SP3; 7 for Server 2003 SP2; 7 for Vista Gold, SP1, and SP2; and 7 for Server 2008 SP2 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by calling the setCapture method on a collection of crafted objects, aka "Uninitialized Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-06-09T14:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-06-15T17:06:44.839-04:00">DRAFT</status_change>
            <status_change date="2009-07-06T04:00:55.213-04:00">INTERIM</status_change>
            <status_change date="2009-07-21T07:46:08.873-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6295 - Modified GDR/LDR service branch format to read easier, removed duplicate, and updated extended def for Vista." date="2011-01-31T14:26:00.351-05:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-01-31T14:26:58.580-05:00">INTERIM</status_change>
            <status_change date="2011-02-21T04:01:07.157-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:25:05.430-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:16.462-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6295 - extended definitions of OS are without SP checks" date="2014-07-28T17:41:00.906-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:42:54.097-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:11.426-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows XP x86, x64">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16850" test_ref="oval:org.mitre.oval:tst:10212"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.21045" test_ref="oval:org.mitre.oval:tst:10207"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16850" test_ref="oval:org.mitre.oval:tst:10212"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.21045" test_ref="oval:org.mitre.oval:tst:10207"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16851" test_ref="oval:org.mitre.oval:tst:9914"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.21046" test_ref="oval:org.mitre.oval:tst:10068"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows Vista x86/x64, all Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6001.18248" test_ref="oval:org.mitre.oval:tst:9929"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6001.22418" test_ref="oval:org.mitre.oval:tst:9978"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows Vista x86/x64, Server 2008 x86/64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6002.18024" test_ref="oval:org.mitre.oval:tst:9840"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6002.22121" test_ref="oval:org.mitre.oval:tst:10061"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6294" version="7" class="vulnerability">
      <metadata>
        <title>HTML Objects Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1530" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1530"/>
        <description>Use-after-free vulnerability in Microsoft Internet Explorer 7 for Windows XP SP2 and SP3; 7 for Server 2003 SP2; 7 for Vista Gold, SP1, and SP2; and 7 for Server 2008 SP2 allows remote attackers to execute arbitrary code by repeatedly adding HTML document nodes and calling event handlers, which triggers an access of an object that (1) was not properly initialized or (2) is deleted, aka "HTML Objects Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-06-09T14:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-06-15T17:06:46.145-04:00">DRAFT</status_change>
            <modified comment="Updated title" date="2009-06-16T10:32:00.713-04:00">
              <contributor organization="The MITRE Corporation">Brendan Miles</contributor>
            </modified>
            <status_change date="2009-07-06T04:00:54.330-04:00">INTERIM</status_change>
            <status_change date="2009-07-21T07:46:08.199-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6294 - Modified GDR/LDR service branch format to read easier, removed duplicate, and updated extended def for Vista." date="2011-01-31T14:25:00.128-05:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-01-31T14:26:17.330-05:00">INTERIM</status_change>
            <status_change date="2011-02-21T04:01:06.380-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:25:04.733-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:16.236-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6294 - extended definitions of OS are without SP checks" date="2014-07-28T17:41:00.906-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:42:53.861-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:11.199-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows XP x86, x64">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16850" test_ref="oval:org.mitre.oval:tst:10212"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.21045" test_ref="oval:org.mitre.oval:tst:10207"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16850" test_ref="oval:org.mitre.oval:tst:10212"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.21045" test_ref="oval:org.mitre.oval:tst:10207"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16851" test_ref="oval:org.mitre.oval:tst:9914"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.21046" test_ref="oval:org.mitre.oval:tst:10068"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows Vista x86/x64, all Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6001.18248" test_ref="oval:org.mitre.oval:tst:9929"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6001.22418" test_ref="oval:org.mitre.oval:tst:9978"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows Vista x86/x64, Server 2008 x86/64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6002.18024" test_ref="oval:org.mitre.oval:tst:9840"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6002.22121" test_ref="oval:org.mitre.oval:tst:10061"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6287" version="6" class="vulnerability">
      <metadata>
        <title>Print Spooler Load Library Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0230" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0230"/>
        <description>The Windows Print Spooler in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 allows remote authenticated users to gain privileges via a crafted RPC message that triggers loading of a DLL file from an arbitrary directory, aka "Print Spooler Load Library Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-06-09T14:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-06-15T17:07:12.886-04:00">DRAFT</status_change>
            <status_change date="2009-07-06T04:00:52.996-04:00">INTERIM</status_change>
            <status_change date="2009-07-21T07:46:07.137-04:00">ACCEPTED</status_change>
            <modified comment="Changed operation attribute to 'greater than or equals'" date="2010-02-10T13:05:00.517-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2010-02-10T13:05:55.293-05:00">INTERIM</status_change>
            <modified comment="Changed operation attribute to 'greater than or equals'" date="2010-02-10T13:05:00.923-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2010-03-01T04:00:09.786-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6287 - Modified GDR/LDR service branch format to read easier, removed duplicate, and updated extended def for Vista." date="2011-01-31T14:24:00.552-05:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-01-31T14:25:01.617-05:00">INTERIM</status_change>
            <status_change date="2011-02-21T04:01:05.555-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5160 - contains tests with modified comments and all dependences" date="2014-02-13T12:19:00.287-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:22:58.297-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:15.893-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable on Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Win32spl.dll version is less than 5.0.2195.7266" test_ref="oval:org.mitre.oval:tst:9847"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows XP x86 SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="Localspl.dll version is less than 5.1.2600.3569" test_ref="oval:org.mitre.oval:tst:9961"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows XP x86 SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Localspl.dll version is less than 5.1.2600.5809" test_ref="oval:org.mitre.oval:tst:9871"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="Localspl.dll version is less than 5.2.3790.4509" test_ref="oval:org.mitre.oval:tst:10030"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Vista x86/x64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Localspl.dll version is less than 6.0.6000.16850" test_ref="oval:org.mitre.oval:tst:9868"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Localspl.dll version is less than 6.0.6000.21045" test_ref="oval:org.mitre.oval:tst:9990"/>
              <criterion comment="Localspl.dll version is greater than 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9895"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Vista x86/x64 SP1, all Server 2008 x86/x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Localspl.dll version is less than 6.0.6001.18247" test_ref="oval:org.mitre.oval:tst:9461"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Localspl.dll version is less than 6.0.6001.22417" test_ref="oval:org.mitre.oval:tst:10052"/>
              <criterion comment="Localspl.dll version is greater than 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9965"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Vista x86/x64 SP2, Server 2008 x86/64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Localspl.dll version is less than 6.0.6002.18024" test_ref="oval:org.mitre.oval:tst:9971"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Localspl.dll version is less than 6.0.6002.22120" test_ref="oval:org.mitre.oval:tst:9717"/>
              <criterion comment="Localspl.dll version is greater than 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:9903"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6278" version="7" class="vulnerability">
      <metadata>
        <title>Cross-Domain Information Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1140" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1140"/>
        <description>Microsoft Internet Explorer 5.01 SP4; 6 SP1; 6 and 7 for Windows XP SP2 and SP3; 6 and 7 for Server 2003 SP2; 7 for Vista Gold, SP1, and SP2; and 7 for Server 2008 SP2 does not prevent HTML rendering of cached content, which allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Cross-Domain Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-06-09T14:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-06-15T17:06:39.608-04:00">DRAFT</status_change>
            <status_change date="2009-07-06T04:00:51.972-04:00">INTERIM</status_change>
            <status_change date="2009-07-21T07:46:06.326-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6278 - Modified GDR/LDR service branch format to read easier, removed duplicate, and updated extended def for Vista." date="2011-01-31T14:23:00.564-05:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-01-31T14:23:58.272-05:00">INTERIM</status_change>
            <status_change date="2011-02-21T04:01:04.674-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:25:02.057-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:15.649-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6278 - extended definitions of OS are without SP checks" date="2014-07-28T17:41:00.906-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:42:50.362-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:10.814-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 5.01 on Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="Mshtml.dll version is less than 5.0.3877.2200" test_ref="oval:org.mitre.oval:tst:9429"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1627" test_ref="oval:org.mitre.oval:tst:9757"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on Windows XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3562" test_ref="oval:org.mitre.oval:tst:9989"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on Windows XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5803" test_ref="oval:org.mitre.oval:tst:10078"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on all Windows XP x64, Server 2003 x86,x64,ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4504" test_ref="oval:org.mitre.oval:tst:9507"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows XP x86, x64">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16850" test_ref="oval:org.mitre.oval:tst:10212"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.21045" test_ref="oval:org.mitre.oval:tst:10207"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16850" test_ref="oval:org.mitre.oval:tst:10212"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.21045" test_ref="oval:org.mitre.oval:tst:10207"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16851" test_ref="oval:org.mitre.oval:tst:9914"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.21046" test_ref="oval:org.mitre.oval:tst:10068"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows Vista x86/x64, all Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6001.18248" test_ref="oval:org.mitre.oval:tst:9929"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6001.22418" test_ref="oval:org.mitre.oval:tst:9978"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows Vista x86/x64, Server 2008 x86/64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6002.18024" test_ref="oval:org.mitre.oval:tst:9840"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6002.22121" test_ref="oval:org.mitre.oval:tst:10061"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6277" version="6" class="vulnerability">
      <metadata>
        <title>Win32k Insufficient Data Validation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2513" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2513"/>
        <description>The Graphics Device Interface (GDI) in win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Insufficient Data Validation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-10T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-11-12T15:32:30.205-05:00">DRAFT</status_change>
            <status_change date="2009-11-30T04:00:28.957-05:00">INTERIM</status_change>
            <status_change date="2009-12-21T04:00:53.568-05:00">ACCEPTED</status_change>
            <modified comment="Changed operation attribute to 'greater than or equals'" date="2010-02-10T13:05:00.517-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2010-02-10T13:05:54.585-05:00">INTERIM</status_change>
            <modified comment="Changed operation attribute to 'greater than or equals'" date="2010-02-10T13:05:00.923-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2010-03-01T04:00:08.950-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6277 - Modified GDR/LDR service branch format to read easier, removed duplicate, and updated extended def for Vista." date="2011-01-31T14:22:00.962-05:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-01-31T14:23:26.037-05:00">INTERIM</status_change>
            <status_change date="2011-02-21T04:01:03.654-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5160 - contains tests with modified comments and all dependences" date="2014-02-13T12:19:00.287-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:22:55.501-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:15.395-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable on Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of win32k.sys is less than 5.0.2195.7322" test_ref="oval:org.mitre.oval:tst:11065"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows XP x86 SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="the version of win32k.sys is less than 5.1.2600.3614" test_ref="oval:org.mitre.oval:tst:10898"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows XP x86 SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of win32k.sys is less than 5.1.2600.5863" test_ref="oval:org.mitre.oval:tst:11060"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of win32k.sys is less than 5.2.3790.4571" test_ref="oval:org.mitre.oval:tst:10856"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Vista x86/x64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of win32k.sys is less than 6.0.6000.16908" test_ref="oval:org.mitre.oval:tst:10258"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of win32k.sys is less than 6.0.6000.21108" test_ref="oval:org.mitre.oval:tst:10947"/>
              <criterion comment="the version of win32k.sys is greater than 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9977"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Vista x86/x64 SP1, all Server 2008 x86/x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of win32k.sys is less than 6.0.6001.18311" test_ref="oval:org.mitre.oval:tst:11103"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of win32k.sys is less than 6.0.6001.22497" test_ref="oval:org.mitre.oval:tst:10753"/>
              <criterion comment="the version of win32k.sys is greater than 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:10142"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Vista x86/x64 SP2, Server 2008 x86/64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of win32k.sys is less than 6.0.6002.18091" test_ref="oval:org.mitre.oval:tst:10883"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of win32k.sys is less than 6.0.6002.22200" test_ref="oval:org.mitre.oval:tst:11097"/>
              <criterion comment="the version of win32k.sys is greater than 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10124"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6271" version="3" class="vulnerability">
      <metadata>
        <title>DHTML Editing Component ActiveX Control Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2519" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2519"/>
        <description>The DHTML Editing Component ActiveX control in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly format HTML markup, which allows remote attackers to execute arbitrary code via a crafted web site that triggers "system state" corruption, aka "DHTML Editing Component ActiveX Control Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-08T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-09-12T20:28:13.661-04:00">DRAFT</status_change>
            <status_change date="2009-09-28T04:00:19.279-04:00">INTERIM</status_change>
            <status_change date="2009-10-19T04:00:13.279-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:206 - modified vulnerabilities ofÂ MS Visual C++ Â  (winsxs folder checks were modified)" date="2014-04-17T13:09:00.881-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-04-17T13:11:49.542-04:00">INTERIM</status_change>
            <status_change date="2014-05-05T04:00:28.644-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Triedit.dll is less than 6.1.0.9235" test_ref="oval:org.mitre.oval:tst:10246"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of Triedit.dll is less than 6.1.0.9246" test_ref="oval:org.mitre.oval:tst:10543"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6264" version="3" class="vulnerability">
      <metadata>
        <title>Windows Kernel NULL Pointer Dereference Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2516" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2516"/>
        <description>The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold and SP1, and Server 2008 Gold does not properly validate data sent from user mode, which allows local users to gain privileges via a crafted PE .exe file that triggers a NULL pointer dereference during chain traversal, aka "Windows Kernel NULL Pointer Dereference Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-13T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-10-22T17:36:47.222-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:43.086-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:27.582-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6264 - For 2003 itanium platform, updated with the proper file (Ntkrnlmp.exe) as given in the bulletin" date="2011-10-04T13:19:00.233-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-10-04T13:20:37.162-04:00">INTERIM</status_change>
            <status_change date="2011-10-24T04:00:22.972-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 5.0.2195.7319" test_ref="oval:org.mitre.oval:tst:10573"/>
        </criteria>
        <criteria operator="AND" comment="Windows XP x86 SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 5.1.2600.3610" test_ref="oval:org.mitre.oval:tst:10847"/>
        </criteria>
        <criteria operator="AND" comment="Windows XP x86 SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of Ntoskrnl.exe is less than 5.1.2600.5857" test_ref="oval:org.mitre.oval:tst:11004"/>
        </criteria>
        <criteria operator="AND" comment="Windows XP x64 SP2, Windows Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR" comment="OS check for Windows XP (x64) SP2 or Windows 2003">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
          </criteria>
          <criterion comment="the version of Ntoskrnl.exe is less than 5.2.3790.4566" test_ref="oval:org.mitre.oval:tst:10965"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Server 2003 ia64 SP2">
          <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          <criterion comment="the version of Ntkrnlmp.exe is less than 5.2.3790.4566" test_ref="oval:org.mitre.oval:tst:44068"/>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64">
          <criteria operator="OR" comment="OS check for Windows Vista (x86/x64)">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6000.16901" test_ref="oval:org.mitre.oval:tst:10944"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:10762"/>
              <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6000.21101" test_ref="oval:org.mitre.oval:tst:10113"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64 SP1, Windows Server 2008 x86/x64/ia64 SP1">
          <criteria operator="OR" comment="OS check for Windows Vista SP1 or 2008 Server">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6001.18304" test_ref="oval:org.mitre.oval:tst:10438"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:10407"/>
              <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6001.22489" test_ref="oval:org.mitre.oval:tst:10918"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64 SP2, Windows Server 2008 x86/x64/ia64 SP2">
          <criteria operator="OR" comment="OS check for Windows Vista SP2 or 2008 Server SP2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6002.18082" test_ref="oval:org.mitre.oval:tst:10866"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10581"/>
              <criterion comment="the version of Ntoskrnl.exe is less than 6.0.6002.22191" test_ref="oval:org.mitre.oval:tst:10957"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6260" version="7" class="vulnerability">
      <metadata>
        <title>HTML Object Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1528" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1528"/>
        <description>Microsoft Internet Explorer 6 and 7 for Windows XP SP2 and SP3; 6 and 7 for Server 2003 SP2; 7 for Vista Gold, SP1, and SP2; and 7 for Server 2008 SP2 does not properly synchronize AJAX requests, which allows allows remote attackers to execute arbitrary code via a large number of concurrent, asynchronous XMLHttpRequest calls, aka "HTML Object Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-06-09T14:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-06-15T17:06:43.919-04:00">DRAFT</status_change>
            <modified comment="Updated title" date="2009-06-16T10:32:00.713-04:00">
              <contributor organization="The MITRE Corporation">Brendan Miles</contributor>
            </modified>
            <status_change date="2009-07-06T04:00:50.398-04:00">INTERIM</status_change>
            <status_change date="2009-07-21T07:46:05.248-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6260 - Modified GDR/LDR service branch format to read easier, removed duplicate, and updated extended def for Vista." date="2011-01-31T14:20:00.924-05:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-01-31T14:21:31.380-05:00">INTERIM</status_change>
            <status_change date="2011-02-21T04:01:02.791-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:25:06.973-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:15.101-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6260 - extended definitions of OS are without SP checks" date="2014-07-28T17:41:00.906-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:42:52.787-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:10.456-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 6 on Windows XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3562" test_ref="oval:org.mitre.oval:tst:9989"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on Windows XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5803" test_ref="oval:org.mitre.oval:tst:10078"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on all Windows XP x64, Server 2003 x86,x64,ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4504" test_ref="oval:org.mitre.oval:tst:9507"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows XP x86, x64">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16850" test_ref="oval:org.mitre.oval:tst:10212"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.21045" test_ref="oval:org.mitre.oval:tst:10207"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16850" test_ref="oval:org.mitre.oval:tst:10212"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.21045" test_ref="oval:org.mitre.oval:tst:10207"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16851" test_ref="oval:org.mitre.oval:tst:9914"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.21046" test_ref="oval:org.mitre.oval:tst:10068"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows Vista x86/x64, all Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6001.18248" test_ref="oval:org.mitre.oval:tst:9929"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6001.22418" test_ref="oval:org.mitre.oval:tst:9978"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows Vista x86/x64, Server 2008 x86/64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6002.18024" test_ref="oval:org.mitre.oval:tst:9840"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6002.22121" test_ref="oval:org.mitre.oval:tst:10061"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6253" version="8" class="vulnerability">
      <metadata>
        <title>Active Directory Memory Leak Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1139" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1139"/>
        <description>Memory leak in the LDAP service in Active Directory on Microsoft Windows 2000 SP4 and Server 2003 SP2, and Active Directory Application Mode (ADAM) on Windows XP SP2 and SP3 and Server 2003 SP2, allows remote attackers to cause a denial of service (memory consumption and service outage) via (1) LDAP or (2) LDAPS requests with unspecified OID filters, aka "Active Directory Memory Leak Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-06-09T14:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-06-15T17:06:23.798-04:00">DRAFT</status_change>
            <status_change date="2009-07-06T04:00:49.150-04:00">INTERIM</status_change>
            <status_change date="2009-07-21T07:46:04.829-04:00">ACCEPTED</status_change>
            <modified comment="Added test for checking if system is used as AD" date="2009-09-05T12:00:00.035-04:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2009-09-14T04:00:17.999-04:00">INTERIM</status_change>
            <status_change date="2009-10-05T04:00:05.918-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:5285 - obj:5285 is pointing to windows\system32 directory. But, adamdsa.dll file by default will be in windows\ADAM directory" date="2011-07-14T10:24:00.833-04:00">
              <contributor organization="SecPod Technologies">Sharath S</contributor>
            </modified>
            <status_change date="2011-07-14T10:26:45.439-04:00">INTERIM</status_change>
            <status_change date="2011-08-01T04:00:56.852-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6253 - modified vulnerabilities which check the version of file adamdsa.dll" date="2013-12-18T16:36:00.218-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-18T16:44:41.050-05:00">INTERIM</status_change>
            <status_change date="2014-01-06T04:00:48.296-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:89195 - bulletin MS14-016, for the month of Mar 2014." date="2014-03-18T14:40:00.553-04:00">
              <contributor organization="SecPod Technologies">Pooja Shetty</contributor>
            </modified>
            <status_change date="2014-03-18T14:42:04.096-04:00">INTERIM</status_change>
            <status_change date="2014-04-07T04:06:55.913-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="NTDS Service is installed" test_ref="oval:org.mitre.oval:tst:42615"/>
          <criterion comment="Ntdsa.dll version is less than 5.0.2195.7292" test_ref="oval:org.mitre.oval:tst:10236"/>
          <criterion comment="the system is being used as AD - DomainRole is 4 or 5" test_ref="oval:org.mitre.oval:tst:10696"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
          </criteria>
          <criteria operator="OR" comment="Active Directory or ADAM">
            <criteria operator="AND">
              <criterion comment="NTDS Service is installed" test_ref="oval:org.mitre.oval:tst:42615"/>
              <criterion comment="the system is being used as AD - DomainRole is 4 or 5" test_ref="oval:org.mitre.oval:tst:10696"/>
              <criterion comment="ntdsa.dll version is less than 5.2.3790.4501" test_ref="oval:org.mitre.oval:tst:9685"/>
            </criteria>
            <criteria operator="AND">
              <criterion comment="Check if ADAM service is installed" test_ref="oval:org.mitre.oval:tst:89195"/>
              <criterion comment="adamdsa.dll version is less than 1.1.3790.4503" test_ref="oval:org.mitre.oval:tst:9714"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          </criteria>
          <criterion comment="Check if ADAM service is installed" test_ref="oval:org.mitre.oval:tst:89195"/>
          <criterion comment="adamdsa.dll version is less than 1.1.3790.4501" test_ref="oval:org.mitre.oval:tst:10192"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          <criterion comment="Check if ADAM service is installed" test_ref="oval:org.mitre.oval:tst:89195"/>
          <criterion comment="adamdsa.dll version is less than 1.1.3790.4503" test_ref="oval:org.mitre.oval:tst:9714"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:625" version="4" class="vulnerability">
      <metadata>
        <title>MS FrontPage Server Extensions SmartHTML Denial of Service (Test 4)</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft FrontPage Server Extensions 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0824" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0824"/>
        <description>Unknown vulnerability in the SmartHTML interpreter (shtml.dll) in Microsoft FrontPage Server Extensions 2000 and 2002, and Microsoft SharePoint Team Services 2002, allows remote attackers to cause a denial of service (response failure) via a certain request.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-12-09T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-14T12:00:00.000-04:00" comment="Changed the definition to look at the file shtml.dll instead of fp5awel.dll.  It was determined that this is where the vulnerability (a buffer overflow) actually existed.  Also added the configuration test saying you are vulnerable if the SmartHTML interpreter is enabled.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2004-09-14T09:52:00.000-04:00" comment="XP SP2 added">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-09-15T12:00:00.000-04:00">INTERIM</status_change>
            <modified comment="Corrected to use a forward slash as the separator in the key." date="2007-05-07T15:59:00.964-04:00">
              <contributor organization="Secure Elements, Inc.">Glenn Strickland</contributor>
            </modified>
            <modified comment="Removed reference to test for nt 4.0 and add reference to nt 4.0 inventory definition." date="2008-02-28T12:48:00.621-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Removed reference to test for nt 4.0 and add reference to nt 4.0 inventory definition." date="2008-02-28T12:48:00.621-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Multiple corrections and update to POSIX compatibility for ste:2656" date="2010-11-29T16:12:00.873-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Software section">
          <criteria operator="OR" comment="Windows NT, 2000, or XP is installed">
            <extend_definition comment="Microsoft Windows NT is installed" definition_ref="oval:org.mitre.oval:def:36"/>
            <criterion comment="Windows 2000 is installed" test_ref="oval:org.mitre.oval:tst:3085"/>
            <criterion comment="Windows XP is installed" test_ref="oval:org.mitre.oval:tst:2838"/>
          </criteria>
          <criterion comment="a vulnerable version of shtml.dll exists (FPSE 2002 or SPTS 2003)" test_ref="oval:org.mitre.oval:tst:2490"/>
          <criterion negate="true" comment="Win2K/XP/2003 service pack 2 (or later) is installed" test_ref="oval:org.mitre.oval:tst:2837"/>
        </criteria>
        <criteria operator="AND" comment="Configuration section">
          <criterion comment="FrontPage Server Extensions 2002 are enabled (NT, 2K, XP)" test_ref="oval:org.mitre.oval:tst:2677"/>
          <criterion comment="SmartHTML interpreter is enabled" test_ref="oval:org.mitre.oval:tst:2705"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:624" version="2" class="vulnerability">
      <metadata>
        <title>Exchange Server 5.5 TNEF Decoding Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Outlook</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0002" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0002"/>
        <description>Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-11T12:56:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-12T09:21:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-01T09:08:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.382-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-10-25T16:53:15.979-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:01:20.045-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Exchange 5.5 with SP4 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2492"/>
        <criterion comment="the version of Mapi32.dll is less than 5.5.2658.34" negate="false" test_ref="oval:org.mitre.oval:tst:2491"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6237" version="4" class="vulnerability">
      <metadata>
        <title>DirectX NULL Byte Overwrite Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>DirectX</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1537" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1537"/>
        <description>Unspecified vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted QuickTime media file, as exploited in the wild in May 2009, aka "DirectX NULL Byte Overwrite Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-05-29T10:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-06-05T14:03:42.812-04:00">DRAFT</status_change>
            <status_change date="2009-06-22T04:00:31.605-04:00">INTERIM</status_change>
            <status_change date="2009-07-13T04:00:53.369-04:00">ACCEPTED</status_change>
            <modified comment="Updated title and removed criteria for DirectX 9.0 on Windows XP SP1 and Server 2003 SP1. Also corrected comments on DirectX related tests and changed tests to check for less than version x.y.z." date="2009-07-20T07:58:00.890-04:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2009-07-20T08:12:38.908-04:00">INTERIM</status_change>
            <status_change date="2009-08-10T04:00:06.657-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:3502 - obj/ste updates to conform to authoring style guide" date="2013-03-26T09:53:00.500-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-03-26T09:55:56.145-04:00">INTERIM</status_change>
            <status_change date="2013-04-15T04:00:28.654-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="DirectX 7 on Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="DirectX 7.0x Installed" test_ref="oval:org.mitre.oval:tst:1296"/>
          <criterion comment="the version of Quartz.dll is less than 6.1.9.736" test_ref="oval:org.mitre.oval:tst:10181"/>
        </criteria>
        <criteria operator="AND" comment="DirectX 8.1 on Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="DirectX 8.1 Installed" test_ref="oval:org.mitre.oval:tst:6805"/>
          <criterion comment="the version of Quartz.dll is less than 6.3.1.893" test_ref="oval:org.mitre.oval:tst:10229"/>
        </criteria>
        <criteria operator="AND" comment="DirectX 9.0 on Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="DirectX 9.0x Installed" test_ref="oval:org.mitre.oval:tst:601"/>
          <criterion comment="the version of Quartz.dll is less than 6.5.1.911" test_ref="oval:org.mitre.oval:tst:10131"/>
        </criteria>
        <criteria operator="AND" comment="DirectX 9.0 on Win XP SP2 x86">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="DirectX 9.0x Installed" test_ref="oval:org.mitre.oval:tst:601"/>
          <criterion comment="the version of Quartz.dll is less than 6.5.2600.3580" test_ref="oval:org.mitre.oval:tst:10177"/>
        </criteria>
        <criteria operator="AND" comment="DirectX 9.0 on Win XP SP3 x86">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="DirectX 9.0x Installed" test_ref="oval:org.mitre.oval:tst:601"/>
          <criterion comment="the version of Quartz.dll is less than 6.5.2600.5822" test_ref="oval:org.mitre.oval:tst:10081"/>
        </criteria>
        <criteria operator="AND" comment="DirectX 9.0 on Windows XP SP2, Server 2003 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="DirectX 9.0x Installed" test_ref="oval:org.mitre.oval:tst:601"/>
          <criterion comment="the version of Quartz.dll is less than 6.5.3790.4523" test_ref="oval:org.mitre.oval:tst:10047"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6233" version="2" class="vulnerability" deprecated="true">
      <metadata>
        <title>WinINet Credential Reflection Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0550" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0550"/>
        <description>Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008; and WinINet in Microsoft Internet Explorer 5.01 SP4, 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on Windows Server 2003 SP1 and SP2, 7 on Windows Vista Gold and SP1, and 7 on Windows Server 2008; allows remote web servers to capture and replay NTLM credentials, and execute arbitrary code, via vectors related to absence of a "credential-reflection protections" opt-in step, aka "Windows HTTP Services Credential Reflection Vulnerability" and "WinINet Credential Reflection Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-04-14T16:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-04-17T16:44:51.303-04:00">DRAFT</status_change>
            <status_change date="2009-05-04T04:00:37.006-04:00">INTERIM</status_change>
            <status_change date="2009-05-25T04:02:09.263-04:00">ACCEPTED</status_change>
            <modified comment="Removed Microsoft reference" date="2009-06-01T16:05:28.035-04:00">
              <contributor organization="The MITRE Corporation">Brendan Miles</contributor>
            </modified>
            <status_change date="2009-06-08T04:01:03.500-04:00">INTERIM</status_change>
            <status_change date="2009-06-29T04:01:05.570-04:00">ACCEPTED</status_change>
            <modified comment="Deprecated after consolidating other definitions for the same CVE. The new consolidated definition is oval:org.mitre.oval:def:7569" date="2010-01-03T18:00:11.513-04:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2010-01-03T18:00:11.513-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="Mshtml.dll version is less than 5.0.3874.1900" test_ref="oval:org.mitre.oval:tst:9783"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1625" test_ref="oval:org.mitre.oval:tst:9684"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3527" test_ref="oval:org.mitre.oval:tst:9744"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5764" test_ref="oval:org.mitre.oval:tst:9622"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.3304" test_ref="oval:org.mitre.oval:tst:9395"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4470" test_ref="oval:org.mitre.oval:tst:9788"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP1 is installed" definition_ref="oval:org.mitre.oval:def:720"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:4386"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.3304" test_ref="oval:org.mitre.oval:tst:9395"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4470" test_ref="oval:org.mitre.oval:tst:9788"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP1 is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.3304" test_ref="oval:org.mitre.oval:tst:9395"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4470" test_ref="oval:org.mitre.oval:tst:9788"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
            <extend_definition comment="Microsoft Windows XP x64 Edition SP1 is installed" definition_ref="oval:org.mitre.oval:def:720"/>
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16825" test_ref="oval:org.mitre.oval:tst:9976"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
            <extend_definition comment="Microsoft Windows XP x64 Edition SP1 is installed" definition_ref="oval:org.mitre.oval:def:720"/>
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21015" test_ref="oval:org.mitre.oval:tst:9705"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:4386"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP1 is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16825" test_ref="oval:org.mitre.oval:tst:9976"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:4386"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP1 is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21015" test_ref="oval:org.mitre.oval:tst:9705"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16830" test_ref="oval:org.mitre.oval:tst:9688"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21023" test_ref="oval:org.mitre.oval:tst:10115"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.16000" test_ref="oval:org.mitre.oval:tst:9444"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.18226" test_ref="oval:org.mitre.oval:tst:10150"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.22389" test_ref="oval:org.mitre.oval:tst:10005"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6231" version="6" class="vulnerability">
      <metadata>
        <title>Windows Kernel Pointer Validation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1124" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1124"/>
        <description>The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate user-mode pointers in unspecified error conditions, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Pointer Validation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-06-09T14:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-06-15T17:07:25.323-04:00">DRAFT</status_change>
            <status_change date="2009-07-06T04:00:46.238-04:00">INTERIM</status_change>
            <status_change date="2009-07-21T07:46:03.535-04:00">ACCEPTED</status_change>
            <modified comment="Changed operation attribute to 'greater than or equals'" date="2010-02-10T13:05:00.517-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2010-02-10T13:05:54.242-05:00">INTERIM</status_change>
            <modified comment="Changed operation attribute to 'greater than or equals'" date="2010-02-10T13:05:00.923-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2010-03-01T04:00:08.218-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6231 - Modified GDR/LDR service branch format to read easier, removed duplicate, and updated extended def for Vista." date="2011-01-31T14:20:00.020-05:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-01-31T14:20:36.130-05:00">INTERIM</status_change>
            <status_change date="2011-02-21T04:01:01.948-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5160 - contains tests with modified comments and all dependences" date="2014-02-13T12:19:00.287-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:22:56.547-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:14.859-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable on Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of win32k.sys is less than 5.0.2195.7279" test_ref="oval:org.mitre.oval:tst:10057"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows XP x86 SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="the version of win32k.sys is less than 5.1.2600.3556" test_ref="oval:org.mitre.oval:tst:10075"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows XP x86 SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of win32k.sys is less than 5.1.2600.5796" test_ref="oval:org.mitre.oval:tst:9735"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of win32k.sys is less than 5.2.3790.4497" test_ref="oval:org.mitre.oval:tst:9867"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Vista x86/x64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of win32k.sys is less than 6.0.6000.16849" test_ref="oval:org.mitre.oval:tst:10055"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of win32k.sys is less than 6.0.6000.21044" test_ref="oval:org.mitre.oval:tst:9650"/>
              <criterion comment="the version of win32k.sys is greater than 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9977"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Vista x86/x64 SP1, all Server 2008 x86/x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of win32k.sys is less than 6.0.6001.18246" test_ref="oval:org.mitre.oval:tst:9997"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of win32k.sys is less than 6.0.6001.22416" test_ref="oval:org.mitre.oval:tst:10213"/>
              <criterion comment="the version of win32k.sys is greater than 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:10142"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Vista x86/x64 SP2, Server 2008 x86/64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of win32k.sys is less than 6.0.6002.18023" test_ref="oval:org.mitre.oval:tst:9699"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of win32k.sys is less than 6.0.6002.22119" test_ref="oval:org.mitre.oval:tst:9663"/>
              <criterion comment="the version of win32k.sys is greater than 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10124"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6228" version="3" class="vulnerability">
      <metadata>
        <title>DNS Server Query Validation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0233" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0233"/>
        <description>The DNS Resolver Cache Service (aka DNSCache) in Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008, when dynamic updates are enabled, does not reuse cached DNS responses in all applicable situations, which makes it easier for remote attackers to predict transaction IDs and poison caches by simultaneously sending crafted DNS queries and responses, aka "DNS Server Query Validation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-03-10T16:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-03-13T20:23:52.929-04:00">DRAFT</status_change>
            <status_change date="2009-03-30T04:00:24.626-04:00">INTERIM</status_change>
            <status_change date="2009-04-20T04:00:24.299-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6228 - - &quot;def:5715 updated to included missing LDR support.&quot; - &quot;def:6138 updated by removing non-vuln Win2008 criteria.&quot; - &quot;def:6117 updated do merged all common criteria.&quot;. - &quot;def:6228 updated to included missing LDR support.&quot;" date="2011-10-27T09:52:00.232-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2011-10-27T10:01:17.802-04:00">INTERIM</status_change>
            <status_change date="2011-11-14T04:00:59.175-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Microsoft Windows Server 2000 SP4 is installed and version of dns.exe">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of dns.exe is less than 5.0.2195.7260" test_ref="oval:org.mitre.oval:tst:9653"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Windows Server 2003 SP1 (x86/x64/ia64) is installed and file version of dns.exe">
          <criteria operator="OR" comment="Microsoft Windows Server 2003 SP1 (x86/x64/ia64) is installed">
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:4386"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
          </criteria>
          <criterion comment="the version of dns.exe is less than 5.2.3790.3295" test_ref="oval:org.mitre.oval:tst:9777"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Windows Server 2003 SP2 (x86/x64/ia64) is installed and file versions of dns.exe">
          <criteria operator="OR" comment="Microsoft Windows Server 2003 SP2 (x86/x64/ia64) is installed">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of dns.exe is less than 5.2.3790.4460" test_ref="oval:org.mitre.oval:tst:9346"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Windows Server 2008 (x86/x64) is installed and file version of dns.exe">
          <criteria operator="OR" comment="Microsoft Windows Server 2008 (x86/x64) is installed">
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criteria operator="OR" comment="version of dns.exe less than 6.0.6001.18214 or greater than or equal 6.0.6001.22000 and less than 6.0.6001.22375">
            <criterion comment="the version of dns.exe is less than 6.0.6001.18214" test_ref="oval:org.mitre.oval:tst:9751"/>
            <criteria operator="AND" comment="For LDR file version greater than or equal 6.0.6001.22000 and less than 6.0.6001.22375">
              <criterion comment="the version of dns.exe is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:44438"/>
              <criterion comment="the version of dns.exe is less than 6.0.6001.22375" test_ref="oval:org.mitre.oval:tst:44142"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6227" version="6" class="vulnerability">
      <metadata>
        <title>RPC Marshalling Engine Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0568" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0568"/>
        <description>The RPC Marshalling Engine (aka NDR) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly maintain its internal state, which allows remote attackers to overwrite arbitrary memory locations via a crafted RPC message that triggers incorrect pointer reading, related to "IDL interfaces containing a non-conformant varying array" and FC_SMVARRAY, FC_LGVARRAY, FC_VARIABLE_REPEAT, and FC_VARIABLE_OFFSET, aka "RPC Marshalling Engine Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-06-09T14:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-06-15T17:07:32.087-04:00">DRAFT</status_change>
            <status_change date="2009-07-06T04:00:45.235-04:00">INTERIM</status_change>
            <status_change date="2009-07-21T07:46:02.795-04:00">ACCEPTED</status_change>
            <modified comment="Changed operation attribute to 'greater than or equals'" date="2010-02-10T13:05:00.517-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2010-02-10T13:05:53.809-05:00">INTERIM</status_change>
            <modified comment="Changed operation attribute to 'greater than or equals'" date="2010-02-10T13:05:00.923-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2010-03-01T04:00:07.360-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6227 - Modified GDR/LDR service branch format to read easier, removed duplicate, and updated extended def for Vista." date="2011-01-31T14:19:00.663-05:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-01-31T14:19:37.833-05:00">INTERIM</status_change>
            <status_change date="2011-02-21T04:01:01.166-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5160 - contains tests with modified comments and all dependences" date="2014-02-13T12:19:00.287-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:23:04.254-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:14.412-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable on Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of rpcrt4.dll is less than 5.0.2195.7281" test_ref="oval:org.mitre.oval:tst:10050"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows XP x86 SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="the version of rpcrt4.dll is less than 5.1.2600.3555" test_ref="oval:org.mitre.oval:tst:10162"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows XP x86 SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of rpcrt4.dll is less than 5.1.2600.5795" test_ref="oval:org.mitre.oval:tst:9906"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of rpcrt4.dll is less than 5.2.3790.4502" test_ref="oval:org.mitre.oval:tst:9939"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Vista x86/x64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of rpcrt4.dll is less than 6.0.6000.16850" test_ref="oval:org.mitre.oval:tst:10152"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of rpcrt4.dll is less than 6.0.6000.21045" test_ref="oval:org.mitre.oval:tst:9790"/>
              <criterion comment="the version of rpcrt4.dll is greater than 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:10086"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Vista x86/x64 SP1, all Server 2008 x86/x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of rpcrt4.dll is less than 6.0.6001.18247" test_ref="oval:org.mitre.oval:tst:9930"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of rpcrt4.dll is less than 6.0.6001.22417" test_ref="oval:org.mitre.oval:tst:10151"/>
              <criterion comment="the version of rpcrt4.dll is greater than 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:10014"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Vista x86/x64 SP2, Server 2008 x86/64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of rpcrt4.dll is less than 6.0.6002.18024" test_ref="oval:org.mitre.oval:tst:9919"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of rpcrt4.dll is less than 6.0.6002.22120" test_ref="oval:org.mitre.oval:tst:9987"/>
              <criterion comment="the version of rpcrt4.dll is greater than 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10194"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6226" version="3" class="vulnerability">
      <metadata>
        <title>Avast! Home and Professional 'aswMon2.sys' Stack-based Buffer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Avast! AntiVirus</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3522" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3522"/>
        <description>Stack-based buffer overflow in aswMon2.sys in Avast! Home and Professional for Windows 4.8.1351, and possibly other versions before 4.8.1356, allows local users to cause a denial of service (system crash) and possibly gain privileges via a crafted IOCTL request to IOCTL 0xb2c80018.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-25T10:27:31.430-04:00">
              <contributor organization="SecPod Technologies">Sharath S</contributor>
            </submitted>
            <status_change date="2009-11-25T13:47:36.813-05:00">DRAFT</status_change>
            <status_change date="2009-12-14T04:00:08.462-05:00">INTERIM</status_change>
            <status_change date="2010-01-04T04:01:44.267-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:592 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:27:16.300-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:18.938-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Avast! AntiVirus is installed" definition_ref="oval:org.mitre.oval:def:6558"/>
        <criterion comment="Avast! version is less than 4.8.1356.0" test_ref="oval:org.mitre.oval:tst:10746"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6209" version="3" class="vulnerability">
      <metadata>
        <title>MS-CHAP Authentication Bypass Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3677" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3677"/>
        <description>The Internet Authentication Service (IAS) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold and SP1, and Server 2008 Gold does not properly verify the credentials in an MS-CHAP v2 Protected Extensible Authentication Protocol (PEAP) authentication request, which allows remote attackers to access network resources via a malformed request, aka "MS-CHAP Authentication Bypass Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-09T17:00:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2009-12-11T11:34:39.610-05:00">DRAFT</status_change>
            <status_change date="2009-12-28T04:00:25.564-05:00">INTERIM</status_change>
            <status_change date="2010-01-18T04:00:05.370-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6209 - modified comments" date="2014-02-28T15:13:00.247-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-28T15:16:19.261-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:25.337-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="2004 SP4 or later and Raschap.dll">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Raschap.dll is less than 5.0.2195.7344" test_ref="oval:org.mitre.oval:tst:11137"/>
        </criteria>
        <criteria operator="AND" comment="XP SP2 x86 and Raschap.dll">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="the version of Raschap.dll is less than 5.1.2600.3632" test_ref="oval:org.mitre.oval:tst:11108"/>
        </criteria>
        <criteria operator="AND" comment="XP SP3 x86 and Raschap.dll">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of Raschap.dll is less than 5.1.2600.5886" test_ref="oval:org.mitre.oval:tst:10249"/>
        </criteria>
        <criteria operator="AND" comment="2004 SP4 or later and Raschap.dll">
          <criteria operator="OR" comment="XP SP2 x64\2003 SP2 x86\x64\ia64">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of Raschap.dll is less than 5.2.3790.4600" test_ref="oval:org.mitre.oval:tst:11014"/>
        </criteria>
        <criteria operator="AND" comment="2Vosta x86 and Raschap.dll">
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <criterion comment="the version of Raschap.dll is less than 6.0.6000.16932" test_ref="oval:org.mitre.oval:tst:10954"/>
          <criterion comment="the version of Raschap.dll is greater than or equal 6.0.6000.16000" test_ref="oval:org.mitre.oval:tst:11160"/>
        </criteria>
        <criteria operator="AND" comment="Vista x86 and Raschap.dll">
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <criterion comment="the version of Raschap.dll is less than 6.0.6000.21134" test_ref="oval:org.mitre.oval:tst:10760"/>
          <criterion comment="the version of Raschap.dll is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:11135"/>
        </criteria>
        <criteria operator="AND" comment="Vista SP1 x86\x64 or Server 2008 x86\x64\ia64 and Raschap.dll">
          <criteria operator="OR" comment="Vista SP1 x86\x64 or Server 2008 x86\x64\ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of Raschap.dll is less than 6.0.6001.18336" test_ref="oval:org.mitre.oval:tst:11106"/>
          <criterion comment="the version of Raschap.dll is greater than or equal 6.0.6001.18000" test_ref="oval:org.mitre.oval:tst:11246"/>
        </criteria>
        <criteria operator="AND" comment="Vista SP1 x86\x64 or 2008 x86\x64\ia64 and Raschap.dll">
          <criteria operator="OR" comment="Vista SP1 x86\x64 or Server 2008 x86\x64\ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of Raschap.dll is less than 6.0.6001.22536" test_ref="oval:org.mitre.oval:tst:11153"/>
          <criterion comment="the version of Raschap.dll is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:11057"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6206" version="6" class="vulnerability">
      <metadata>
        <title>Windows Kernel Desktop Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1123" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1123"/>
        <description>The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Desktop Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-06-09T14:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-06-15T17:07:24.222-04:00">DRAFT</status_change>
            <status_change date="2009-07-06T04:00:43.847-04:00">INTERIM</status_change>
            <status_change date="2009-07-21T07:46:02.108-04:00">ACCEPTED</status_change>
            <modified comment="Changed operation attribute to 'greater than or equals'" date="2010-02-10T13:05:00.517-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2010-02-10T13:05:55.572-05:00">INTERIM</status_change>
            <modified comment="Changed operation attribute to 'greater than or equals'" date="2010-02-10T13:05:00.923-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2010-03-01T04:00:06.536-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6206 - Modified GDR/LDR service branch format to read easier, removed duplicate, and updated extended def for Vista." date="2011-01-31T14:18:00.346-05:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-01-31T14:19:05.389-05:00">INTERIM</status_change>
            <status_change date="2011-02-21T04:01:00.358-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5160 - contains tests with modified comments and all dependences" date="2014-02-13T12:19:00.287-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:22:57.734-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:14.133-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable on Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of win32k.sys is less than 5.0.2195.7279" test_ref="oval:org.mitre.oval:tst:10057"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows XP x86 SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="the version of win32k.sys is less than 5.1.2600.3556" test_ref="oval:org.mitre.oval:tst:10075"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows XP x86 SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of win32k.sys is less than 5.1.2600.5796" test_ref="oval:org.mitre.oval:tst:9735"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of win32k.sys is less than 5.2.3790.4497" test_ref="oval:org.mitre.oval:tst:9867"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Vista x86/x64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of win32k.sys is less than 6.0.6000.16849" test_ref="oval:org.mitre.oval:tst:10055"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of win32k.sys is less than 6.0.6000.21044" test_ref="oval:org.mitre.oval:tst:9650"/>
              <criterion comment="the version of win32k.sys is greater than 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9977"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Vista x86/x64 SP1, all Server 2008 x86/x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of win32k.sys is less than 6.0.6001.18246" test_ref="oval:org.mitre.oval:tst:9997"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of win32k.sys is less than 6.0.6001.22416" test_ref="oval:org.mitre.oval:tst:10213"/>
              <criterion comment="the version of win32k.sys is greater than 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:10142"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Vista x86/x64 SP2, Server 2008 x86/64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of win32k.sys is less than 6.0.6002.18023" test_ref="oval:org.mitre.oval:tst:9699"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of win32k.sys is less than 6.0.6002.22119" test_ref="oval:org.mitre.oval:tst:9663"/>
              <criterion comment="the version of win32k.sys is greater than 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10124"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6202" version="5" class="vulnerability">
      <metadata>
        <title>Windows Kernel Input Validation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0081" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0081"/>
        <description>The graphics device interface (GDI) implementation in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate input received from user mode, which allows remote attackers to execute arbitrary code via a crafted (1) Windows Metafile (aka WMF) or (2) Enhanced Metafile (aka EMF) image file, aka "Windows Kernel Input Validation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-03-10T16:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-03-13T20:23:57.255-04:00">DRAFT</status_change>
            <status_change date="2009-03-30T04:00:23.874-04:00">INTERIM</status_change>
            <status_change date="2009-04-20T04:00:23.210-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6202 - Updated LDR criteria for Win-Vista &amp; Win-2008." date="2011-10-03T15:38:00.951-04:00">
              <contributor organization="SecPod Technologies">Pradeep R B</contributor>
            </modified>
            <status_change date="2011-10-03T15:39:53.767-04:00">INTERIM</status_change>
            <status_change date="2011-10-24T04:00:22.191-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4525 - contains tests with modified comments and all dependences" date="2014-02-13T12:19:00.287-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:23:14.050-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:13.877-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for Microsoft Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of win32k.sys is less than 5.0.2195.7251" test_ref="oval:org.mitre.oval:tst:8764"/>
        </criteria>
        <criteria operator="AND" comment="Check for Microsoft Windows XP (x86) SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="the version of win32k.sys is less than 5.1.2600.3521" test_ref="oval:org.mitre.oval:tst:9733"/>
        </criteria>
        <criteria operator="AND" comment="Check for Microsoft Windows XP (x86) SP3">
          <criterion comment="the version of win32k.sys is less than 5.1.2600.5756" test_ref="oval:org.mitre.oval:tst:9386"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
        </criteria>
        <criteria operator="AND" comment="Check for Windows Server 2003 (ia64) SP1/Windows Server 2003 SP1 (x86)/Windows Server 2003 SP1 (x64)/Windows XP Professional x64 Edition">
          <criteria operator="OR" comment="Windows Server 2003 (ia64) SP1/Windows Server 2003 SP1 (x86)/Windows Server 2003 SP1 (x64)/Windows XP Professional x64 Edition">
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:4386"/>
            <extend_definition comment="Microsoft Windows XP Professional x64 Edition SP1 is installed" definition_ref="oval:org.mitre.oval:def:720"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
          </criteria>
          <criterion comment="the version of win32k.sys is less than 5.2.3790.3291" test_ref="oval:org.mitre.oval:tst:9426"/>
        </criteria>
        <criteria operator="AND" comment="Check for Windows Server 2003 (ia64) SP2/Windows Server 2003 SP2 (x64)/Windows XP x64 Edition SP2/Windows Server 2003 SP2 (x86)">
          <criteria operator="OR" comment="Windows Server 2003 (ia64) SP2/Windows Server 2003 SP2 (x64)/Windows XP x64 Edition SP2/Windows Server 2003 SP2 (x86)">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of win32k.sys is less than 5.2.3790.4456" test_ref="oval:org.mitre.oval:tst:8835"/>
        </criteria>
        <criteria operator="AND" comment="Check for Windows Vista x64 Edition/Microsoft Windows Vista (32-bit)">
          <criteria operator="OR" comment="Windows Vista x64 Edition/Microsoft Windows Vista (32-bit)">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criterion comment="the version of win32k.sys is less than 6.0.6000.16816" test_ref="oval:org.mitre.oval:tst:9608"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="the version of win32k.sys is greater than 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9977"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6000.21006" test_ref="oval:org.mitre.oval:tst:44149"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for Windows Vista x64 Edition Service Pack 1/Windows Server 2008 (64-bit)/Windows Server 2008 (ia-64)/Microsoft Windows Vista (32-bit)/Microsoft Windows Server 2008 (32-bit) Service Pack 1">
          <criteria operator="OR" comment="Windows Vista x64 Edition Service Pack 1/Windows Server 2008 (64-bit)/Windows Server 2008 (ia-64)/Microsoft Windows Vista (32-bit)/Microsoft Windows Server 2008 (32-bit) Service Pack 1">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criterion comment="the version of win32k.sys is less than 6.0.6001.18211" test_ref="oval:org.mitre.oval:tst:8799"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="the version of win32k.sys is greater than 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:10142"/>
              <criterion comment="Check if version of win32k.sys is less than 6.0.6001.22372" test_ref="oval:org.mitre.oval:tst:43675"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6190" version="7" class="vulnerability">
      <metadata>
        <title>Uninitialized Memory Corruption Vulnerability (CVE-2009-2530)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2530" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2530"/>
        <description>Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-2531.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-13T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-10-22T17:36:43.803-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:40.024-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:24.865-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6190 - Modified GDR/LDR service branch format to read easier, removed duplicate, and updated extended def for Vista." date="2011-01-31T14:17:00.474-05:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-01-31T14:18:17.555-05:00">INTERIM</status_change>
            <status_change date="2011-02-21T04:00:59.379-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:25:08.895-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:13.577-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6190 - extended definitions of OS are without SP checks" date="2014-07-28T17:41:00.906-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:42:53.580-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:09.668-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE6/Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1638" test_ref="oval:org.mitre.oval:tst:10604"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on Windows XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3627" test_ref="oval:org.mitre.oval:tst:10771"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on Windows XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5880" test_ref="oval:org.mitre.oval:tst:10838"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on all Windows XP x64, Server 2003 x86,x64,ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4589" test_ref="oval:org.mitre.oval:tst:10917"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows XP x86, x64">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16915" test_ref="oval:org.mitre.oval:tst:10949"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.21115" test_ref="oval:org.mitre.oval:tst:10971"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16915" test_ref="oval:org.mitre.oval:tst:10949"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.21115" test_ref="oval:org.mitre.oval:tst:10971"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16916" test_ref="oval:org.mitre.oval:tst:10612"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.21116" test_ref="oval:org.mitre.oval:tst:10668"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows Vista x86/x64, all Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6001.18319" test_ref="oval:org.mitre.oval:tst:10928"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6001.22508" test_ref="oval:org.mitre.oval:tst:10959"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows Vista x86/x64, Server 2008 x86/64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6002.18100" test_ref="oval:org.mitre.oval:tst:10793"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6002.22212" test_ref="oval:org.mitre.oval:tst:10952"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Windows XP x86, x64, Server 2003 x86/x64 , Vista x86/x64, x86 SP2, Server 2008 x86/x64, x86/x64 SP2">
          <criteria operator="OR" comment="OS section">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 8.0.6001.18828" test_ref="oval:org.mitre.oval:tst:10824"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
              <criterion comment="Mshtml.dll version is less than 8.0.6001.22918" test_ref="oval:org.mitre.oval:tst:10966"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6186" version="8" class="vulnerability">
      <metadata>
        <title>Integer Overflow in X.509 Object Identifiers Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft ASN.1 Library</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2511" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2511"/>
        <description>Integer overflow in the CryptoAPI component in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows man-in-the-middle attackers to spoof arbitrary SSL servers and other entities via an X.509 certificate that has a malformed ASN.1 Object Identifier (OID) and was issued by a legitimate Certification Authority, aka "Integer Overflow in X.509 Object Identifiers Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-13T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-10-22T17:37:07.588-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:39.286-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:24.133-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6186 - LDR version criteria are added for Vista &amp; 2008, and also added non-root criterion comments" date="2011-10-04T13:16:00.750-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-10-04T13:19:21.125-04:00">INTERIM</status_change>
            <status_change date="2011-10-24T04:00:21.159-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:47.978-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:47.978-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:09.124-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6186 - extended definitions of OS are without SP checks" date="2014-07-28T17:49:00.293-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:51:15.270-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:09.389-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <criterion comment="the version of msasn1.dll is less than 5.0.2195.7334" test_ref="oval:org.mitre.oval:tst:10655"/>
        </criteria>
        <criteria operator="AND" comment="Windows XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="the version of msasn1.dll is less than 5.1.2600.3624" test_ref="oval:org.mitre.oval:tst:10905"/>
        </criteria>
        <criteria operator="AND" comment="Windows XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="the version of msasn1.dll is less than 5.1.2600.5875" test_ref="oval:org.mitre.oval:tst:10731"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64, Windows Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Operating System Check">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <criterion comment="the version of msasn1.dll is less than 5.2.3790.4584" test_ref="oval:org.mitre.oval:tst:10013"/>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64">
          <criteria operator="OR" comment="Operating System Check">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of msasn1.dll is less than 6.0.6000.16922" test_ref="oval:org.mitre.oval:tst:10512"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of msasn1.dll is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:44028"/>
              <criterion comment="the version of msasn1.dll is less than 6.0.6000.21122" test_ref="oval:org.mitre.oval:tst:43659"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64, Windows Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Operating System Check">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of msasn1.dll is less than 6.0.6001.18326" test_ref="oval:org.mitre.oval:tst:10835"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of msasn1.dll is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:44222"/>
              <criterion comment="the version of msasn1.dll is less than 6.0.6001.22515" test_ref="oval:org.mitre.oval:tst:43926"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64, Windows Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Operating System Check">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of msasn1.dll is less than 6.0.6002.18106" test_ref="oval:org.mitre.oval:tst:10818"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of msasn1.dll is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:44044"/>
              <criterion comment="the version of msasn1.dll is less than 6.0.6002.22218" test_ref="oval:org.mitre.oval:tst:44105"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64">
          <criteria operator="OR" comment="Operating System Check">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of msasn1.dll is less than 6.1.7600.16415" test_ref="oval:org.mitre.oval:tst:10587"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of msasn1.dll is greater than or equal 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:10901"/>
              <criterion comment="the version of msasn1.dll is less than 6.1.7600.20518" test_ref="oval:org.mitre.oval:tst:10706"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6184" version="1" class="vulnerability">
      <metadata>
        <title>WMP Heap Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Windows Media Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2527" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2527"/>
        <description>Heap-based buffer overflow in Microsoft Windows Media Player 6.4 allows remote attackers to execute arbitrary code via (1) a crafted ASF file or (2) crafted streaming content, aka "WMP Heap Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-13T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-10-22T17:37:00.718-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:38.885-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:23.762-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
        </criteria>
        <extend_definition comment="Windows Media Player 6.4 is installed." definition_ref="oval:org.mitre.oval:def:6408"/>
        <criterion comment="the version of strmdll.dll is less than 4.1.0.3938" test_ref="oval:org.mitre.oval:tst:10752"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6180" version="1" class="vulnerability">
      <metadata>
        <title>Active Directory Invalid Free Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1138" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1138"/>
        <description>The LDAP service in Active Directory on Microsoft Windows 2000 SP4 does not properly free memory for LDAP and LDAPS requests, which allows remote attackers to execute arbitrary code via a request that uses hexadecimal encoding, whose associated memory is not released, related to a "DN AttributeValue," aka "Active Directory Invalid Free Vulnerability."  NOTE: this issue is probably a memory leak.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-06-09T14:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-06-15T17:06:17.581-04:00">DRAFT</status_change>
            <status_change date="2009-07-06T04:00:42.120-04:00">INTERIM</status_change>
            <status_change date="2009-07-21T07:46:01.806-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
        <criterion comment="Ntdsa.dll version is less than 5.0.2195.7292" test_ref="oval:org.mitre.oval:tst:10236"/>
        <criteria operator="OR">
          <criterion comment="the system is being used as AD" test_ref="oval:org.mitre.oval:tst:9160"/>
          <criterion comment="the system is being used as AD" test_ref="oval:org.mitre.oval:tst:9106"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6166" version="3" class="vulnerability">
      <metadata>
        <title>Virtual PC and Virtual Server Privileged Instruction Decoding Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Virtual Server 2005</product>
          <product>Microsoft Virtual PC 2004</product>
          <product>Microsoft Virtual PC 2007</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1542" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1542"/>
        <description>The Virtual Machine Monitor (VMM) in Microsoft Virtual PC 2004 SP1, 2007, and 2007 SP1, and Microsoft Virtual Server 2005 R2 SP1, does not enforce CPU privilege-level requirements for all machine instructions, which allows guest OS users to execute arbitrary kernel-mode code and gain privileges within the guest OS via a crafted application, aka "Virtual PC and Virtual Server Privileged Instruction Decoding Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-07-14T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-07-20T15:51:35.232-04:00">DRAFT</status_change>
            <status_change date="2009-08-10T04:00:06.156-04:00">INTERIM</status_change>
            <status_change date="2009-08-31T04:00:08.267-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6166 - - def:6166, Microsoft Virtual Server 2005 criteria added according to bulletin revision 2. - obj:2423 is updated to use the proper registry key." date="2011-10-27T10:17:00.608-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-10-27T10:20:08.656-04:00">INTERIM</status_change>
            <status_change date="2011-11-14T04:00:58.694-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Microsoft Virtual PC 2004 SP1">
          <extend_definition comment="Microsoft Virtual PC 2004 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:2177"/>
          <criterion comment="The version of VMM.sys is less than 1.1.465.15" test_ref="oval:org.mitre.oval:tst:9798"/>
        </criteria>
        <criteria comment="Microsoft Virtual PC 2007">
          <extend_definition comment="Microsoft Virtual PC 2007 is installed" definition_ref="oval:org.mitre.oval:def:5854"/>
          <criterion comment="The version of VMM.sys is less than 1.1.598.0" test_ref="oval:org.mitre.oval:tst:10244"/>
        </criteria>
        <criteria comment="Microsoft Virtual PC 2007 SP1">
          <extend_definition comment="Microsoft Virtual PC 2007 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:6324"/>
          <criterion comment="The version of VMM.sys is less than 1.1.656.0" test_ref="oval:org.mitre.oval:tst:10406"/>
        </criteria>
        <criteria comment="Microsoft Virtual Server 2005 R2 Enterprise">
          <extend_definition comment="Microsoft Virtual Server 2005 R2 is installed" definition_ref="oval:org.mitre.oval:def:6342"/>
          <criterion comment="The version of VMM.sys is less than 1.1.656.0" test_ref="oval:org.mitre.oval:tst:10406"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Virtual Server 2005">
          <criteria operator="OR" comment="Check Microsoft Virtual Server 2005 Standard or Enterprise">
            <extend_definition comment="Microsoft Virtual Server 2005 Enterprise is installed" definition_ref="oval:org.mitre.oval:def:2220"/>
            <extend_definition comment="Microsoft Virtual Server 2005 Standard is installed" definition_ref="oval:org.mitre.oval:def:2119"/>
          </criteria>
          <criterion comment="The version of VMM.sys is less than 1.1.465.16" test_ref="oval:org.mitre.oval:tst:44366"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6342" version="5" class="inventory">
      <metadata>
        <title>Microsoft Virtual Server 2005 R2 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Virtual Server 2005 R2</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:virtual_server:2005:r2"/>
        <description>The application Microsoft Virtual Server 2005 R2 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-07-14T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-07-20T15:51:35.080-04:00">DRAFT</status_change>
            <status_change date="2009-08-10T04:00:10.944-04:00">INTERIM</status_change>
            <status_change date="2009-08-31T04:00:13.951-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6342 - Modifications vary from minor OVAL title/description changes to suggesting an alternative CPE name to use." date="2011-09-28T11:29:00.976-04:00">
              <contributor organization="The MITRE Corporation">David Rothenberg</contributor>
            </modified>
            <status_change date="2011-09-28T11:33:33.474-04:00">INTERIM</status_change>
            <status_change date="2011-10-17T04:00:22.585-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6342 - Added product info to inventory" date="2015-05-12T14:25:00.628-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-05-12T14:28:56.094-04:00">INTERIM</status_change>
            <status_change date="2015-06-01T04:00:23.534-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Microsoft Virtual Server 2005 R2 Service Pack 1, Enterprise Edition is installed" test_ref="oval:org.mitre.oval:tst:10032"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6324" version="1" class="inventory">
      <metadata>
        <title>Microsoft Virtual PC 2007 Service Pack 1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:virtual_pc:2007:sp1"/>
        <description>The application Microsoft Virtual PC 2007 Service Pack 1 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-07-14T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-07-20T15:51:34.701-04:00">DRAFT</status_change>
            <status_change date="2009-08-10T04:00:08.326-04:00">INTERIM</status_change>
            <status_change date="2009-08-31T04:00:11.552-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Microsoft Virtual PC 2007 Service Pack 1 is installed" test_ref="oval:org.mitre.oval:tst:10104"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5854" version="1" class="inventory">
      <metadata>
        <title>Microsoft Virtual PC 2007 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:virtual_pc:2007"/>
        <description>The application Microsoft Virtual PC 2007 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-07-14T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-07-20T15:51:34.497-04:00">DRAFT</status_change>
            <status_change date="2009-08-10T04:00:05.145-04:00">INTERIM</status_change>
            <status_change date="2009-08-31T04:00:06.732-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Microsoft Virtual PC 2007 is installed" test_ref="oval:org.mitre.oval:tst:10031"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2220" version="3" class="inventory">
      <metadata>
        <title>Microsoft Virtual Server 2005 Enterprise is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Virtual Server 2005</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:virtual_server:2005::enterprise"/>
        <description>The application Microsoft Virtual Server 2005 Enterprise is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-16T14:45:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-08-20T07:56:42.451-04:00">DRAFT</status_change>
            <status_change date="2007-09-06T09:13:32.616-04:00">INTERIM</status_change>
            <status_change date="2007-09-27T08:57:46.885-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2220 - Added product info to inventory" date="2015-05-12T14:25:00.628-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-05-12T14:28:56.172-04:00">INTERIM</status_change>
            <status_change date="2015-06-01T04:00:13.995-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Microsoft Virtual Server 2005 Enterprise is installed" test_ref="oval:org.mitre.oval:tst:3460"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2177" version="1" class="inventory">
      <metadata>
        <title>Microsoft Virtual PC 2004 Service Pack 1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:virtual_pc:2004:sp1"/>
        <description>The application Microsoft Virtual PC 2004 Service Pack 1 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-16T14:45:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-08-20T07:56:42.337-04:00">DRAFT</status_change>
            <status_change date="2007-09-06T09:13:31.874-04:00">INTERIM</status_change>
            <status_change date="2007-09-27T08:57:45.837-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Microsoft Virtual PC 2004 Service Pack 1 is installed" test_ref="oval:org.mitre.oval:tst:3530"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2119" version="5" class="inventory">
      <metadata>
        <title>Microsoft Virtual Server 2005 Standard is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Virtual Server 2005</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:virtual_server:2005::std"/>
        <description>The application Microsoft Virtual Server 2005 Standard is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-16T14:45:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-08-20T07:56:42.399-04:00">DRAFT</status_change>
            <status_change date="2007-09-06T09:13:30.805-04:00">INTERIM</status_change>
            <status_change date="2007-09-27T08:57:44.665-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:2423 - - def:6166, Microsoft Virtual Server 2005 criteria added according to bulletin revision 2. - obj:2423 is updated to use the proper registry key." date="2011-10-27T10:17:00.608-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-10-27T10:20:08.008-04:00">INTERIM</status_change>
            <status_change date="2011-11-14T04:00:19.400-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2119 - Added product info to inventory" date="2015-05-12T14:25:00.628-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-05-12T14:28:56.261-04:00">INTERIM</status_change>
            <status_change date="2015-06-01T04:00:13.636-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Microsoft Virtual Server 2005 Standard is installed" test_ref="oval:org.mitre.oval:tst:4165"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6164" version="5" class="vulnerability">
      <metadata>
        <title>Page Transition Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0551" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0551"/>
        <description>Microsoft Internet Explorer 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on Windows Server 2003 SP1 and SP2, 7 on Windows Vista Gold and SP1, and 7 on Windows Server 2008 does not properly handle transition errors in a request for one HTTP document followed by a request for a second HTTP document, which allows remote attackers to execute arbitrary code via vectors involving (1) multiple crafted pages on a web site or (2) a web page with crafted inline content such as banner advertisements, aka "Page Transition Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-04-14T16:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-04-17T16:44:54.291-04:00">DRAFT</status_change>
            <status_change date="2009-05-04T04:00:34.414-04:00">INTERIM</status_change>
            <status_change date="2009-05-25T04:02:03.711-04:00">ACCEPTED</status_change>
            <modified comment="Removed Microsoft reference" date="2009-06-01T16:05:28.035-04:00">
              <contributor organization="The MITRE Corporation">Brendan Miles</contributor>
            </modified>
            <status_change date="2009-06-08T04:01:00.525-04:00">INTERIM</status_change>
            <status_change date="2009-06-29T04:01:02.549-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6164 - extended definitions of OS are without SP checks" date="2014-07-28T17:41:00.906-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:42:52.334-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:09.166-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE6/Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1625" test_ref="oval:org.mitre.oval:tst:9684"/>
        </criteria>
        <criteria operator="AND" comment="IE6/XP">
          <extend_definition comment="Microsoft Windows XP is installed" definition_ref="oval:org.mitre.oval:def:105"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3527" test_ref="oval:org.mitre.oval:tst:9744"/>
        </criteria>
        <criteria operator="AND" comment="IE6/XP">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5764" test_ref="oval:org.mitre.oval:tst:9622"/>
        </criteria>
        <criteria operator="AND" comment="IE6/Server 2003 (32-bit)">
          <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.3304" test_ref="oval:org.mitre.oval:tst:9395"/>
        </criteria>
        <criteria operator="AND" comment="IE6/Server 2003 (32-bit)">
          <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4470" test_ref="oval:org.mitre.oval:tst:9788"/>
        </criteria>
        <criteria operator="AND" comment="IE6/XP x64/Server 2003 x64">
          <criteria operator="OR" comment="XP x64/Server 2003 x64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.3304" test_ref="oval:org.mitre.oval:tst:9395"/>
        </criteria>
        <criteria operator="AND" comment="IE6/XP x64/Server 2003 x64">
          <criteria operator="OR" comment="XP x64/Server 2003 x64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4470" test_ref="oval:org.mitre.oval:tst:9788"/>
        </criteria>
        <criteria operator="AND" comment="IE6/Server 2003 (ia64)">
          <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.3304" test_ref="oval:org.mitre.oval:tst:9395"/>
        </criteria>
        <criteria operator="AND" comment="IE6/Server 2003 (ia64)">
          <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4470" test_ref="oval:org.mitre.oval:tst:9788"/>
        </criteria>
        <criteria operator="AND" comment="IE7/XP x86/x64">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16825" test_ref="oval:org.mitre.oval:tst:9976"/>
        </criteria>
        <criteria operator="AND" comment="IE7/XP x86/x64">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21015" test_ref="oval:org.mitre.oval:tst:9705"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16825" test_ref="oval:org.mitre.oval:tst:9976"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21015" test_ref="oval:org.mitre.oval:tst:9705"/>
        </criteria>
        <criteria operator="AND" comment="Mshtml.dll/Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16830" test_ref="oval:org.mitre.oval:tst:9688"/>
        </criteria>
        <criteria operator="AND" comment="Mshtml.dll/Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21023" test_ref="oval:org.mitre.oval:tst:10115"/>
        </criteria>
        <criteria operator="AND" comment="Mshtml.dll/Vista x86/x64/Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64/Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.16000" test_ref="oval:org.mitre.oval:tst:9444"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.18226" test_ref="oval:org.mitre.oval:tst:10150"/>
        </criteria>
        <criteria operator="AND" comment="Mshtml.dll/Vista x86/x64/Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64/Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.22389" test_ref="oval:org.mitre.oval:tst:10005"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6149" version="6" class="vulnerability">
      <metadata>
        <title>Windows HTTP Services Integer Underflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0086" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0086"/>
        <description>Integer underflow in Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote HTTP servers to execute arbitrary code via crafted parameter values in a response, related to error handling, aka "Windows HTTP Services Integer Underflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-04-14T16:00:00">
              <contributor organization="Gideon Technologies, Inc.">Kyle Key</contributor>
            </submitted>
            <status_change date="2009-04-17T16:44:57.184-04:00">DRAFT</status_change>
            <status_change date="2009-05-04T04:00:32.655-04:00">INTERIM</status_change>
            <status_change date="2009-05-25T04:02:01.602-04:00">ACCEPTED</status_change>
            <modified comment="Removed CVE from title. Removed Microsoft reference" date="2009-06-01T16:05:28.035-04:00">
              <contributor organization="The MITRE Corporation">Brendan Miles</contributor>
            </modified>
            <status_change date="2009-06-08T04:00:59.732-04:00">INTERIM</status_change>
            <status_change date="2009-06-29T04:00:59.533-04:00">ACCEPTED</status_change>
            <modified comment="Edited var:306 - Added beginning anchor to local_variable used in pattern match" date="2010-05-13T15:50:00.065-04:00">
              <contributor organization="The MITRE Corporation">Mike Lah</contributor>
            </modified>
            <status_change date="2010-05-13T15:50:58.310-04:00">INTERIM</status_change>
            <status_change date="2010-05-31T04:00:17.646-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:306 - Added closing anchors for variable regex" date="2013-04-08T11:01:00.574-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-04-08T11:03:32.855-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:17:44.484-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="winhttp.dll version 5.1.2600.3490 or later on Windows 2000 sp4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="system32\winhttp.dll version less than 5.1.2600.3490" test_ref="oval:org.mitre.oval:tst:9822"/>
        </criteria>
        <criteria operator="AND" comment="winhttp.dll versin 5.1.2600.3494 or later on windows xp sp2 x86">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="system32\winhttp.dll version less than 5.1.2600.3494" test_ref="oval:org.mitre.oval:tst:9877"/>
        </criteria>
        <criteria operator="AND" comment="winhttp.dll versin 5.1.2600.5727 or later on windows xp sp3 x86">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="system32\winhttp.dll version less than 5.1.2600.5727" test_ref="oval:org.mitre.oval:tst:9540"/>
        </criteria>
        <criteria operator="AND" comment="winhttp.dll versin 5.2.3790.3262 or later on windows xp sp1 x64">
          <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="system32\winhttp.dll version less than 5.2.3790.3262" test_ref="oval:org.mitre.oval:tst:9795"/>
        </criteria>
        <criteria operator="AND" comment="winhttp.dll versin 5.2.3790.4427 or later on windows xp sp2 x64">
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          <criterion comment="system32\winhttp.dll version less than 5.2.3790.4427" test_ref="oval:org.mitre.oval:tst:9649"/>
        </criteria>
        <criteria operator="AND" comment="winhttp.dll versin 5.2.3790.3262 or later on windows server 2003 sp1 (x86)(x64)(ia64)">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:4386"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP1 is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
          </criteria>
          <criterion comment="Winsxs\winhttp.dll version less than 5.2.3790.3262" test_ref="oval:org.mitre.oval:tst:9580"/>
        </criteria>
        <criteria operator="AND" comment="winhttp.dll versin 5.2.3790.4427 or later on windows server 2003 sp2 (x86)(x64)(ia64)">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="Winsxs\winhttp.dll version less than 5.2.3790.4427" test_ref="oval:org.mitre.oval:tst:9985"/>
        </criteria>
        <criteria operator="AND" comment="winhttp.dll versin 6.0.6000.16786 or later on windows vista GDR (x86)(x64)">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="system32\winhttp.dll version greater than or equal 6.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9951"/>
          <criterion comment="system32\winhttp.dll version less than 6.0.6000.16786" test_ref="oval:org.mitre.oval:tst:9981"/>
        </criteria>
        <criteria operator="AND" comment="winhttp.dll versin 6.0.6000.20971 or later on windows vista LDR (x86)(x64)">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="system32\winhttp.dll version greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9442"/>
          <criterion comment="system32\winhttp.dll version less than 6.0.6000.20971" test_ref="oval:org.mitre.oval:tst:9594"/>
        </criteria>
        <criteria operator="AND" comment="winhttp.dll versin 6.0.6001.18178 or later on windows server 2008 sp1 GDR (x86)(x64)(ia64) and windows vista sp1 GDR (x86)(x64)">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="system32\winhttp.dll version greater than or equal 6.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9762"/>
          <criterion comment="system32\winhttp.dll version less than 6.0.6001.18178" test_ref="oval:org.mitre.oval:tst:9801"/>
        </criteria>
        <criteria operator="AND" comment="winhttp.dll versin 6.0.6001.22323 or later on windows server 2008 sp1 LDR (x86)(x64)(ia64) and windows vista sp1 GDR (x86)(x64)">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="system32\winhttp.dll version greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9825"/>
          <criterion comment="system32\winhttp.dll version less than 6.0.6001.22323" test_ref="oval:org.mitre.oval:tst:9119"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6142" version="5" class="vulnerability">
      <metadata>
        <title>Stack-based buffer overflow in the TEA decoding algorithm in Rhino Software Serv-U</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Rhino Software Serv-U</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4006" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4006"/>
        <description>Stack-based buffer overflow in the TEA decoding algorithm in RhinoSoft Serv-U FTP server 7.0.0.1, 9.0.0.5, and other versions before 9.1.0.0 allows remote attackers to execute arbitrary code via a long hexadecimal string.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-25T18:28:46">
              <contributor organization="SecPod Technologies">Sharath S</contributor>
            </submitted>
            <status_change date="2009-11-25T13:47:56.169-05:00">DRAFT</status_change>
            <status_change date="2009-12-14T04:00:07.978-05:00">INTERIM</status_change>
            <status_change date="2010-01-04T04:01:43.303-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:175 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:26:38.382-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:15.360-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6142 - Typo Corrections" date="2014-05-22T11:03:00.270-04:00">
              <contributor organization="McAfee, Inc.">Jerome Athias</contributor>
            </modified>
            <status_change date="2014-05-22T11:06:06.424-04:00">INTERIM</status_change>
            <status_change date="2014-06-09T04:01:46.056-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Rhino Software Serv-U is installed" definition_ref="oval:org.mitre.oval:def:5875"/>
        <criterion comment="Test for Rhino Software Serv-U version less than 9.1.0.0" test_ref="oval:org.mitre.oval:tst:11096"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6138" version="3" class="vulnerability">
      <metadata>
        <title>DNS Server Vulnerability in WPAD Registration Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0093" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0093"/>
        <description>Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008, when dynamic updates are enabled, does not restrict registration of the "wpad" hostname, which allows remote authenticated users to hijack the Web Proxy Auto-Discovery (WPAD) feature, and conduct man-in-the-middle attacks by spoofing a proxy server, via a Dynamic Update request for this hostname, aka "DNS Server Vulnerability in WPAD Registration Vulnerability," a related issue to CVE-2007-1692.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-03-10T16:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-03-13T20:23:57.765-04:00">DRAFT</status_change>
            <status_change date="2009-03-30T04:00:23.121-04:00">INTERIM</status_change>
            <status_change date="2009-04-20T04:00:22.528-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6138 - - &quot;def:5715 updated to included missing LDR support.&quot; - &quot;def:6138 updated by removing non-vuln Win2008 criteria.&quot; - &quot;def:6117 updated do merged all common criteria.&quot;. - &quot;def:6228 updated to included missing LDR support.&quot;" date="2011-10-27T09:52:00.232-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2011-10-27T10:01:16.247-04:00">INTERIM</status_change>
            <status_change date="2011-11-14T04:00:58.313-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Microsoft Windows Server 2000 SP4 is installed and version of dns.exe">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of dns.exe is less than 5.0.2195.7260" test_ref="oval:org.mitre.oval:tst:9653"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Windows Server 2003 SP1 (x86/x64/ia64) is installed and file version of dns.exe">
          <criteria operator="OR" comment="Microsoft Windows Server 2003 SP1 (x86/x64/ia64) is installed">
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:4386"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
          </criteria>
          <criterion comment="the version of dns.exe is less than 5.2.3790.3295" test_ref="oval:org.mitre.oval:tst:9777"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Windows Server 2003 SP2 (x86/x64/ia64) is installed and file versions of dns.exe">
          <criteria operator="OR" comment="Microsoft Windows Server 2003 SP2 (x86/x64/ia64) is installed">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of dns.exe is less than 5.2.3790.4460" test_ref="oval:org.mitre.oval:tst:9346"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6117" version="3" class="vulnerability">
      <metadata>
        <title>WPAD WINS Server Registration Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0094" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0094"/>
        <description>The WINS server in Microsoft Windows 2000 SP4 and Server 2003 SP1 and SP2 does not restrict registration of the (1) "wpad" and (2) "isatap" NetBIOS names, which allows remote authenticated users to hijack the Web Proxy Auto-Discovery (WPAD) and Intra-Site Automatic Tunnel Addressing Protocol (ISATAP) features, and conduct man-in-the-middle attacks by spoofing a proxy server or ISATAP route, by registering one of these names in the WINS database, aka "WPAD WINS Server Registration Vulnerability," a related issue to CVE-2007-1692.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-03-10T16:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-03-13T20:23:58.362-04:00">DRAFT</status_change>
            <status_change date="2009-03-30T04:00:22.645-04:00">INTERIM</status_change>
            <status_change date="2009-04-20T04:00:21.831-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6117 - - &quot;def:5715 updated to included missing LDR support.&quot; - &quot;def:6138 updated by removing non-vuln Win2008 criteria.&quot; - &quot;def:6117 updated do merged all common criteria.&quot;. - &quot;def:6228 updated to included missing LDR support.&quot;" date="2011-10-27T09:52:00.232-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2011-10-27T10:01:15.533-04:00">INTERIM</status_change>
            <status_change date="2011-11-14T04:00:57.877-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Microsoft Windows Server 2000 SP4 is installed and version of wins.exe">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of wins.exe is less than 5.0.2195.7241" test_ref="oval:org.mitre.oval:tst:9651"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Windows Server 2003 SP1 (x86/x64/ia64) is installed and file version of wins.exe">
          <criteria operator="OR" comment="Microsoft Windows Server 2003 SP1 (x86/x64/ia64) is installed">
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:4386"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
          </criteria>
          <criterion comment="the version of wins.exe is less than 5.2.3790.3281" test_ref="oval:org.mitre.oval:tst:9686"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Windows Server 2003 SP2 (x86/x64/ia64) is installed and file version of wins.exe">
          <criteria operator="OR" comment="Microsoft Windows Server 2003 SP2 (x86/x64/ia64) is installed">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of wins.exe is less than 5.2.3790.4446" test_ref="oval:org.mitre.oval:tst:9532"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6109" version="3" class="vulnerability">
      <metadata>
        <title>MSMQ Null Pointer Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1922" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1922"/>
        <description>The Message Queuing (aka MSMQ) service for Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP2, and Vista Gold does not properly validate unspecified IOCTL request data from user mode before passing this data to kernel mode, which allows local users to gain privileges via a crafted request, aka "MSMQ Null Pointer Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-07-28T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-08-19T14:57:57.944-04:00">DRAFT</status_change>
            <status_change date="2009-09-07T04:00:10.512-04:00">INTERIM</status_change>
            <status_change date="2009-09-28T04:00:14.284-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:10069 - contains tests with modified comments and all dependences" date="2014-02-13T12:19:00.287-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:22:33.416-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:13.393-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4 or later">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="mqrt.dll version is less than 5.0.0.808" test_ref="oval:org.mitre.oval:tst:10493"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="mqrt.dll version is less than 5.1.0.1111" test_ref="oval:org.mitre.oval:tst:10353"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 Edition SP2">
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          <criterion comment="mqrt.dll version is less than 5.2.2007.4530" test_ref="oval:org.mitre.oval:tst:10542"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Server 2003 SP2 (x86)">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <criterion comment="mqrt.dll version is less than 5.2.2007.4530" test_ref="oval:org.mitre.oval:tst:10542"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Server 2003 SP2 (x64)">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
          <criterion comment="mqrt.dll version is less than 5.2.2007.4530" test_ref="oval:org.mitre.oval:tst:10542"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Server 2003 SP2 (ia64)">
          <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          <criterion comment="mqrt.dll version is less than 5.2.2007.4530" test_ref="oval:org.mitre.oval:tst:10542"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista (32-bit)">
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <criteria operator="OR" comment="GDR/LDR">
            <criteria operator="AND" comment="GDR">
              <criterion comment="mqrt.dll version is less than 6.0.6000.16871" test_ref="oval:org.mitre.oval:tst:10187"/>
              <criterion comment="mqrt.dll version is greater than or equal 6.0.6000.16000" test_ref="oval:org.mitre.oval:tst:10433"/>
            </criteria>
            <criteria operator="AND" comment="LDR">
              <criterion comment="mqrt.dll version is less than 6.0.6000.21068" test_ref="oval:org.mitre.oval:tst:10526"/>
              <criterion comment="mqrt.dll version is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:10069"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x64">
          <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          <criteria operator="OR" comment="GDR/LDR">
            <criteria operator="AND" comment="GDR">
              <criterion comment="mqrt.dll version is less than 6.0.6000.16871" test_ref="oval:org.mitre.oval:tst:10187"/>
              <criterion comment="mqrt.dll version is greater than or equal 6.0.6000.16000" test_ref="oval:org.mitre.oval:tst:10433"/>
            </criteria>
            <criteria operator="AND" comment="LDR">
              <criterion comment="mqrt.dll version is less than 6.0.6000.21068" test_ref="oval:org.mitre.oval:tst:10526"/>
              <criterion comment="mqrt.dll version is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:10069"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6108" version="3" class="vulnerability" deprecated="true">
      <metadata>
        <title>Blended Threat Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2540" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2540"/>
        <description>Apple Safari on Mac OS X, and before 3.1.2 on Windows, does not prompt the user before downloading an object that has an unrecognized content type, which allows remote attackers to place malware into the (1) Desktop directory on Windows or (2) Downloads directory on Mac OS X, and subsequently allows remote attackers to execute arbitrary code on Windows by leveraging an untrusted search path vulnerability in (a) Internet Explorer 7 on Windows XP or (b) the SearchPath function in Windows XP, Vista, and Server 2003 and 2008, aka a "Carpet Bomb" and a "Blended Threat Elevation of Privilege Vulnerability," a different issue than CVE-2008-1032. NOTE: Apple considers this a vulnerability only because the Microsoft products can load application libraries from the desktop and, as of 20080619, has not covered the issue in an advisory for Mac OS X.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-04-14T16:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-04-17T16:44:58.190-04:00">DRAFT</status_change>
            <status_change date="2009-05-04T04:00:31.172-04:00">INTERIM</status_change>
            <status_change date="2009-05-25T04:01:59.632-04:00">ACCEPTED</status_change>
            <modified comment="Added Microsoft Windows Vista, Server 2003, XP, 2000 to the list of affected platforms. Removed Microsoft reference" date="2009-06-01T16:05:28.035-04:00">
              <contributor organization="The MITRE Corporation">Brendan Miles</contributor>
            </modified>
            <status_change date="2009-06-08T04:00:58.571-04:00">INTERIM</status_change>
            <status_change date="2009-06-29T04:00:57.786-04:00">ACCEPTED</status_change>
            <status_change date="2010-07-22T10:00:00.000-05:00">DEPRECATED</status_change>
            <modified comment="Deprecating duplicate definition - use def:8509 instead" date="2010-07-22T10:00:00.000-05:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
            <extend_definition comment="Microsoft Windows XP x64 Edition SP1 is installed" definition_ref="oval:org.mitre.oval:def:720"/>
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16825" test_ref="oval:org.mitre.oval:tst:9976"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
            <extend_definition comment="Microsoft Windows XP x64 Edition SP1 is installed" definition_ref="oval:org.mitre.oval:def:720"/>
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21015" test_ref="oval:org.mitre.oval:tst:9705"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6107" version="1" class="vulnerability">
      <metadata>
        <title>Active Directory Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4023" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4023"/>
        <description>Active Directory in Microsoft Windows 2000 SP4 does not properly allocate memory for (1) LDAP and (2) LDAPS requests, which allows remote attackers to execute arbitrary code via a crafted request, aka "Active Directory Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-10-14T13:33:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-10-16T14:01:36.362-04:00">DRAFT</status_change>
            <status_change date="2008-11-03T04:00:26.298-05:00">INTERIM</status_change>
            <status_change date="2008-11-24T04:00:22.138-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Ntdsa.dll version is less than 5.0.2195.7178" test_ref="oval:org.mitre.oval:tst:8600"/>
          <criteria operator="OR">
            <criterion comment="the system is being used as AD" test_ref="oval:org.mitre.oval:tst:9160"/>
            <criterion comment="the system is being used as AD" test_ref="oval:org.mitre.oval:tst:9106"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6095" version="4" class="vulnerability">
      <metadata>
        <title>Event System Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1457" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1457"/>
        <description>The Event System in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate per-user subscriptions, which allows remote authenticated users to execute arbitrary code via a crafted event subscription request.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-13T09:28:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-08-14T15:02:24.008-04:00">DRAFT</status_change>
            <status_change date="2008-09-01T04:01:23.999-04:00">INTERIM</status_change>
            <status_change date="2008-09-22T04:00:40.682-04:00">ACCEPTED</status_change>
            <modified comment="Corrected test comment to reference es.dll instead of Ipsecsvc.dll." date="2009-02-27T15:52:00.695-05:00">
              <contributor organization="Prism Microsystems, Inc.">Maneesh Jolly</contributor>
            </modified>
            <status_change date="2009-03-16T04:00:17.876-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6095 - Added LDR version check &amp; itanium support" date="2011-10-25T14:28:00.689-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2011-10-25T14:31:29.709-04:00">INTERIM</status_change>
            <status_change date="2011-11-14T04:00:57.227-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="win 2000 sp4/version">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of es.dll is less than 2000.2.3550.0" test_ref="oval:org.mitre.oval:tst:9053"/>
        </criteria>
        <criteria operator="AND" comment="win XP SP2/version">
          <criterion comment="the version of es.dll is less than 2001.12.4414.320" test_ref="oval:org.mitre.oval:tst:9013"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
        </criteria>
        <criteria operator="AND" comment="win XP SP3/version">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of es.dll is less than 2001.12.4414.706" test_ref="oval:org.mitre.oval:tst:9019"/>
        </criteria>
        <criteria operator="AND" comment="server 2003 SP1/XP 64 bit/version">
          <criterion comment="the version of es.dll is less than 2001.12.4720.3129" test_ref="oval:org.mitre.oval:tst:9147"/>
          <criteria operator="OR" comment="OS check">
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:4386"/>
            <extend_definition comment="Microsoft Windows XP Professional x64 Edition SP1 is installed" definition_ref="oval:org.mitre.oval:def:720"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="server 2003 SP2/PX SP2 64 bit/version">
          <criterion comment="the version of es.dll is less than 2001.12.4720.4282" test_ref="oval:org.mitre.oval:tst:8200"/>
          <criteria operator="OR" comment="OS check">
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vista/version">
          <extend_definition comment="Microsoft Windows Vista is installed" definition_ref="oval:org.mitre.oval:def:228"/>
          <criteria operator="OR" comment="GDR/LDR">
            <criterion comment="the version of es.dll is less than 2001.12.6930.16677" test_ref="oval:org.mitre.oval:tst:9038"/>
            <criteria operator="AND" comment="LDR range">
              <criterion comment="Check if the version of Es.dll is greater than or equal to 2001.12.6930.20000" test_ref="oval:org.mitre.oval:tst:44426"/>
              <criterion comment="Check if the version of Es.dll is less than 2001.12.6930.20818" test_ref="oval:org.mitre.oval:tst:44006"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="vista sp1/server 2008 sp1/version">
          <criteria operator="OR" comment="OS check">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          </criteria>
          <criteria operator="OR" comment="GDR/LDR">
            <criterion comment="the version of es.dll is less than 2001.12.6931.18057" test_ref="oval:org.mitre.oval:tst:8968"/>
            <criteria operator="AND" comment="LDR range">
              <criterion comment="Check if the version of Es.dll is greater than or equal to 2001.12.6931.22000" test_ref="oval:org.mitre.oval:tst:44378"/>
              <criterion comment="Check if the version of Es.dll is less than 2001.12.6931.22162" test_ref="oval:org.mitre.oval:tst:44340"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6093" version="4" class="vulnerability">
      <metadata>
        <title>Server Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4250" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4250"/>
        <description>The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a crafted RPC request that triggers the overflow during path canonicalization, as exploited in the wild by Gimmiv.A in October 2008, aka "Server Service Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-10-23T15:59:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-10-27T10:19:52.568-04:00">DRAFT</status_change>
            <status_change date="2008-11-17T04:00:41.540-05:00">INTERIM</status_change>
            <status_change date="2008-12-08T04:01:09.358-05:00">ACCEPTED</status_change>
            <modified comment="Corrected that operator for states - 4034, 4472, 4619 and 4236" date="2008-12-12T16:29:00.642-05:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2008-12-12T16:31:57.666-05:00">INTERIM</status_change>
            <status_change date="2008-12-29T04:00:38.759-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6093 - &quot;Added support for Windows Server 2003 SP1 &amp; SP2 for Itanium Edition&quot; and &quot;Removed test criterion tst:8966 &amp; tst:9195, which wasn't required.&quot;" date="2011-10-17T14:45:00.611-04:00">
              <contributor organization="SecPod Technologies">Prashanth A.</contributor>
            </modified>
            <status_change date="2011-10-17T14:47:46.201-04:00">INTERIM</status_change>
            <status_change date="2011-11-07T04:01:04.821-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for vulnerable Windows 2000 SP4 and Netapi32.dll version">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Netapi32.dll version is less than 5.0.2195.7203" test_ref="oval:org.mitre.oval:tst:9230"/>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable Windows XP (x86) SP2 and Netapi32.dll version">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="Netapi32.dll version is less than 5.1.2600.3462" test_ref="oval:org.mitre.oval:tst:9314"/>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable Windows XP (x86) SP3 and Netapi32.dll version">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Netapi32.dll version is less than 5.1.2600.5694" test_ref="oval:org.mitre.oval:tst:9266"/>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable Windows Server 2003 SP1 (x86)/(x64)/(IA-64)/XP x64 SP1 and Netapi32.dll version">
          <criteria operator="OR" comment="Check for vulnerable Windows Server 2003 SP1 (x86)/(x64)/(IA-64)/XP x64 SP1">
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:4386"/>
            <extend_definition comment="Microsoft Windows XP Professional x64 Edition SP1 is installed" definition_ref="oval:org.mitre.oval:def:720"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
          </criteria>
          <criterion comment="Netapi32.dll version is less than 5.2.3790.3229" test_ref="oval:org.mitre.oval:tst:8369"/>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable Windows Server 2003 SP2 (x86)/(x64)/(IA-64)/XP x64 SP2 and Netapi32.dll version">
          <criteria operator="OR" comment="Check for vulnerable Windows Server 2003 SP2 (x86)/(x64)/(IA-64)/XP x64 SP2">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="Netapi32.dll version is less than 5.2.3790.4392" test_ref="oval:org.mitre.oval:tst:9058"/>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable Windows (x64)/(x86) and Netapi32.dll version">
          <criteria operator="OR" comment="Check for vulnerable Windows (x64)/(x86)">
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criteria operator="AND" comment="Check for GDR">
              <criterion comment="Netapi32.dll version is less than 6.0.6000.16764" test_ref="oval:org.mitre.oval:tst:8380"/>
            </criteria>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Netapi32.dll version is greater than 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9199"/>
              <criterion comment="Netapi32.dll version is less than 6.0.6000.20937" test_ref="oval:org.mitre.oval:tst:9223"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable Windows SP1(X86)/(X64)/Server 2008 (X86)/(X64)/(IA-64) and Netapi32.dll version">
          <criteria operator="OR" comment="Check for vulnerable Windows SP1(X86)/(X64)/Server 2008 (X86)/(X64)/(IA-64)">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criteria operator="AND" comment="Check for GDR">
              <criterion comment="Netapi32.dll version is less than 6.0.6001.18157" test_ref="oval:org.mitre.oval:tst:9140"/>
            </criteria>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Netapi32.dll version is greater than 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:8394"/>
              <criterion comment="Netapi32.dll version is less than 6.0.6001.22288" test_ref="oval:org.mitre.oval:tst:9090"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6081" version="3" class="vulnerability">
      <metadata>
        <title>CSS Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0076" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0076"/>
        <description>Microsoft Internet Explorer 7, when XHTML strict mode is used, allows remote attackers to execute arbitrary code via the zoom style directive in conjunction with unspecified other directives in a malformed Cascading Style Sheets (CSS) stylesheet in a crafted HTML document, aka "CSS Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-02-10T16:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-02-13T17:01:51.515-05:00">DRAFT</status_change>
            <status_change date="2009-03-02T04:00:21.048-05:00">INTERIM</status_change>
            <status_change date="2009-03-23T04:00:17.627-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6081 - extended definitions of OS are without SP checks" date="2014-07-28T17:41:00.906-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:42:51.617-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:08.978-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Mshtml.dll/Server 2003 (32-bit)">
          <extend_definition comment="Microsoft Windows XP is installed" definition_ref="oval:org.mitre.oval:def:105"/>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16809" test_ref="oval:org.mitre.oval:tst:9568"/>
        </criteria>
        <criteria operator="AND" comment="Mshtml.dll/Server 2003 (32-bit)">
          <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16809" test_ref="oval:org.mitre.oval:tst:9568"/>
        </criteria>
        <criteria operator="AND" comment="Mshtml.dll/Vista (32-bit)">
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16809" test_ref="oval:org.mitre.oval:tst:9574"/>
        </criteria>
        <criteria operator="AND" comment="Mshtml.dll/Vista (32-bit)">
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.20996" test_ref="oval:org.mitre.oval:tst:9573"/>
        </criteria>
        <criteria operator="AND" comment="Mshtml.dll/Vista (32-bit)">
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.16000" test_ref="oval:org.mitre.oval:tst:9444"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.18203" test_ref="oval:org.mitre.oval:tst:9638"/>
        </criteria>
        <criteria operator="AND" comment="Mshtml.dll/Vista (32-bit)">
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.22355" test_ref="oval:org.mitre.oval:tst:9338"/>
        </criteria>
        <criteria operator="AND" comment="Mshtml.dll/Server 2008 (32-bit)">
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.16000" test_ref="oval:org.mitre.oval:tst:9444"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.18203" test_ref="oval:org.mitre.oval:tst:9638"/>
        </criteria>
        <criteria operator="AND" comment="Mshtml.dll/Server 2008 (32-bit)">
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.22355" test_ref="oval:org.mitre.oval:tst:9338"/>
        </criteria>
        <criteria operator="AND" comment="IE7/XP x64/Server 2003 x64">
          <criteria operator="OR" comment="XP x64/Server 2003 x64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16809" test_ref="oval:org.mitre.oval:tst:9568"/>
        </criteria>
        <criteria operator="AND" comment="IE7/XP x64/Server 2003 x64">
          <criteria operator="OR" comment="XP x64/Server 2003 x64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.20996" test_ref="oval:org.mitre.oval:tst:9573"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x64">
          <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16809" test_ref="oval:org.mitre.oval:tst:9568"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x64">
          <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.20996" test_ref="oval:org.mitre.oval:tst:9573"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x64/Server 2008 x64">
          <criteria operator="OR" comment="Vista x64/Server 2008 x64">
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.16000" test_ref="oval:org.mitre.oval:tst:9444"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.18203" test_ref="oval:org.mitre.oval:tst:9638"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x64/Server 2008 x64">
          <criteria operator="OR" comment="Vista x64/Server 2008 x64">
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.22355" test_ref="oval:org.mitre.oval:tst:9338"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6080" version="3" class="vulnerability">
      <metadata>
        <title>IIS FTP Service RCE and DoS Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3023" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3023"/>
        <description>Buffer overflow in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 6.0 allows remote authenticated users to execute arbitrary code via a crafted NLST (NAME LIST) command that uses wildcards, leading to memory corruption, aka "IIS FTP Service RCE and DoS Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-13T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-10-22T17:37:06.003-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:34.804-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:20.005-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6080 - October Patch Tuesday" date="2011-10-14T16:09:00.325-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-10-14T16:09:57.554-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:04:12.823-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows 2000 SP4 - IIS 5.0 (FTP Service 5.0)">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft IIS 5.0 is installed" definition_ref="oval:org.mitre.oval:def:731"/>
          <criterion comment="The version of ftpsvc2.dll is less than 5.0.2195.7336" test_ref="oval:org.mitre.oval:tst:10425"/>
        </criteria>
        <criteria operator="AND" comment="Windows XP x86 SP2 - IIS 5.1 (FTP Service 5.1)">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <extend_definition comment="Microsoft IIS 5.1 is installed" definition_ref="oval:org.mitre.oval:def:460"/>
          <criterion comment="The version of ftpsvc2.dll is less than 6.0.2600.3624" test_ref="oval:org.mitre.oval:tst:10973"/>
        </criteria>
        <criteria operator="AND" comment="Windows XP x86 SP3 - IIS 5.1 (FTP Service 5.1)">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <extend_definition comment="Microsoft IIS 5.1 is installed" definition_ref="oval:org.mitre.oval:def:460"/>
          <criterion comment="The version of ftpsvc2.dll is less than 6.0.2600.5875" test_ref="oval:org.mitre.oval:tst:10691"/>
        </criteria>
        <criteria operator="AND" comment="Windows XP SP2 x64/Windows 2003 SP2 (x86/x64/ia64) - IIS 6.0 (FTP Service 6.0)">
          <criteria operator="OR" comment="Windows XP SP2 x64/Windows 2003 SP2 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft IIS 6.0 is installed" definition_ref="oval:org.mitre.oval:def:227"/>
          <criterion comment="The version of ftpsvc2.dll is less than 6.0.3790.4584" test_ref="oval:org.mitre.oval:tst:10767"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6072" version="7" class="vulnerability">
      <metadata>
        <title>Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1917" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1917"/>
        <description>Microsoft Internet Explorer 6 SP1; Internet Explorer 6 for Windows XP SP2 and SP3 and Server 2003 SP2; and Internet Explorer 7 and 8 for Windows XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 do not properly handle attempts to access deleted objects in memory, which allows remote attackers to execute arbitrary code via a crafted HTML document that triggers memory corruption, aka "Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-07-28T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-08-03T07:48:12.310-04:00">DRAFT</status_change>
            <status_change date="2009-08-24T04:00:07.036-04:00">INTERIM</status_change>
            <status_change date="2009-09-14T04:00:06.886-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6072 - Created new tests to correct the wrong IE8 mshtml.dll file versions for def:5524, def:6072, def:5660." date="2011-01-31T15:35:00.472-05:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-01-31T15:35:53.841-05:00">INTERIM</status_change>
            <status_change date="2011-02-21T04:00:57.352-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:25:03.002-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:13.022-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6072 - extended definitions of OS are without SP checks" date="2014-07-28T17:41:00.906-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:42:53.054-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:08.724-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 6 on Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1634" test_ref="oval:org.mitre.oval:tst:10442"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on Windows XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3603" test_ref="oval:org.mitre.oval:tst:10058"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on Windows XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5848" test_ref="oval:org.mitre.oval:tst:10127"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on all Windows XP x64, Server 2003 x86,x64,ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4555" test_ref="oval:org.mitre.oval:tst:10273"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows XP x86, x64">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16890" test_ref="oval:org.mitre.oval:tst:9633"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.21089" test_ref="oval:org.mitre.oval:tst:9998"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16890" test_ref="oval:org.mitre.oval:tst:9633"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.21089" test_ref="oval:org.mitre.oval:tst:9998"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16890" test_ref="oval:org.mitre.oval:tst:10074"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.21089" test_ref="oval:org.mitre.oval:tst:10312"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows Vista x86/x64, all Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6001.18294" test_ref="oval:org.mitre.oval:tst:10471"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6001.22475" test_ref="oval:org.mitre.oval:tst:10352"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows Vista x86/x64, Server 2008 x86/64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6002.18071" test_ref="oval:org.mitre.oval:tst:10141"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6002.22180" test_ref="oval:org.mitre.oval:tst:10330"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Windows XP x86/x64, Server 2003 x86/x64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 8.0.6001.18812" test_ref="oval:org.mitre.oval:tst:41916"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
              <criterion comment="Mshtml.dll version is less than 8.0.6001.22902" test_ref="oval:org.mitre.oval:tst:42208"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 8.0.6001.18813" test_ref="oval:org.mitre.oval:tst:42240"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
              <criterion comment="Mshtml.dll version is less than 8.0.6001.22903" test_ref="oval:org.mitre.oval:tst:41308"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:607" version="5" class="vulnerability">
      <metadata>
        <title>Workstation Service Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4691" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4691"/>
        <description>Stack-based buffer overflow in the NetpManageIPCConnect function in the Workstation service (wkssvc.dll) in Microsoft Windows 2000 SP4 and XP SP2 allows remote attackers to execute arbitrary code via NetrJoinDomain2 RPC messages with a long hostname.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-11-15T12:28:05">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-11-17T12:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:54:00.053-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:48.840-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:607 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:06:01.039-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:38.131-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:1448 - Correction of a filename (Spwmp.dll is replaced by wkssvc.dll as per the bulletin info.) in an object oval:org.mitre.oval:obj:1448 along with comments" date="2011-09-14T12:12:00.927-04:00">
              <contributor organization="SecPod Technologies">Pradeep R B</contributor>
            </modified>
            <status_change date="2011-09-14T12:12:57.520-04:00">INTERIM</status_change>
            <status_change date="2011-10-03T04:00:06.894-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win2K,SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of wkssvc.dll is less than 5.0.2195.7108" test_ref="oval:org.mitre.oval:tst:73"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of wkssvc.dll is less than 5.1.2600.2976" test_ref="oval:org.mitre.oval:tst:113"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6069" version="5" class="vulnerability">
      <metadata>
        <title>Uninitialized Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0553" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0553"/>
        <description>Microsoft Internet Explorer 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on Windows Server 2003 SP1 and SP2, 7 on Windows Vista Gold and SP1, and 7 on Windows Server 2008 allows remote attackers to execute arbitrary code via a web page that triggers presence of an object in memory that was (1) not properly initialized or (2) deleted, aka "Uninitialized Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-04-14T16:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-04-17T16:44:58.507-04:00">DRAFT</status_change>
            <status_change date="2009-05-04T04:00:30.593-04:00">INTERIM</status_change>
            <status_change date="2009-05-25T04:01:57.463-04:00">ACCEPTED</status_change>
            <modified comment="Removed CVE from title. Removed Microsoft reference" date="2009-06-01T16:05:28.035-04:00">
              <contributor organization="The MITRE Corporation">Brendan Miles</contributor>
            </modified>
            <status_change date="2009-06-08T04:00:57.501-04:00">INTERIM</status_change>
            <status_change date="2009-06-29T04:00:55.214-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6069 - extended definitions of OS are without SP checks" date="2014-07-28T17:41:00.906-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:42:51.402-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:08.434-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE6/Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1625" test_ref="oval:org.mitre.oval:tst:9684"/>
        </criteria>
        <criteria operator="AND" comment="IE6/XP">
          <extend_definition comment="Microsoft Windows XP is installed" definition_ref="oval:org.mitre.oval:def:105"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3527" test_ref="oval:org.mitre.oval:tst:9744"/>
        </criteria>
        <criteria operator="AND" comment="IE6/XP (32-bit)">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5764" test_ref="oval:org.mitre.oval:tst:9622"/>
        </criteria>
        <criteria operator="AND" comment="IE6/Server 2003 (32-bit)">
          <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.3304" test_ref="oval:org.mitre.oval:tst:9395"/>
        </criteria>
        <criteria operator="AND" comment="IE6/Server 2003 (32-bit)">
          <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4470" test_ref="oval:org.mitre.oval:tst:9788"/>
        </criteria>
        <criteria operator="AND" comment="IE6/XP x64/Server 2003 x64">
          <criteria operator="OR" comment="XP x64/Server 2003 x64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.3304" test_ref="oval:org.mitre.oval:tst:9395"/>
        </criteria>
        <criteria operator="AND" comment="IE6/XP x64/Server 2003 x64">
          <criteria operator="OR" comment="XP x64/Server 2003 x64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4470" test_ref="oval:org.mitre.oval:tst:9788"/>
        </criteria>
        <criteria operator="AND" comment="IE6/Server 2003 ia64">
          <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.3304" test_ref="oval:org.mitre.oval:tst:9395"/>
        </criteria>
        <criteria operator="AND" comment="IE6/Server 2003 ia64">
          <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4470" test_ref="oval:org.mitre.oval:tst:9788"/>
        </criteria>
        <criteria operator="AND" comment="IE7/XP x86/x64">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16825" test_ref="oval:org.mitre.oval:tst:9976"/>
        </criteria>
        <criteria operator="AND" comment="IE7/XP x86/x64">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21015" test_ref="oval:org.mitre.oval:tst:9705"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16825" test_ref="oval:org.mitre.oval:tst:9976"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21015" test_ref="oval:org.mitre.oval:tst:9705"/>
        </criteria>
        <criteria operator="AND" comment="Mshtml.dll/Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16830" test_ref="oval:org.mitre.oval:tst:9688"/>
        </criteria>
        <criteria operator="AND" comment="Mshtml.dll/Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21023" test_ref="oval:org.mitre.oval:tst:10115"/>
        </criteria>
        <criteria operator="AND" comment="Mshtml.dll/Vista x86/x64/Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64/Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.16000" test_ref="oval:org.mitre.oval:tst:9444"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.18226" test_ref="oval:org.mitre.oval:tst:10150"/>
        </criteria>
        <criteria operator="AND" comment="Mshtml.dll/Vista x86/x64/Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64/Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.22389" test_ref="oval:org.mitre.oval:tst:10005"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6062" version="3" class="vulnerability">
      <metadata>
        <title>GDI Heap Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3465" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3465"/>
        <description>Heap-based buffer overflow in an API in GDI in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows context-dependent attackers to cause a denial of service or execute arbitrary code via a WMF file with a malformed file-size parameter, which would not be properly handled by a third-party application that uses this API for a copy operation, aka "GDI Heap Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-12-09T13:31:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-12-12T16:42:32.541-05:00">DRAFT</status_change>
            <status_change date="2008-12-29T04:00:37.730-05:00">INTERIM</status_change>
            <status_change date="2009-01-19T04:00:17.436-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6062 - Inclusion of Win 2003/2008 (IA-64), Vista 64-bit &amp; added LDR support too" date="2011-11-03T15:24:00.015-04:00">
              <contributor organization="SecPod Technologies">Prashanth A.</contributor>
            </modified>
            <status_change date="2011-11-03T15:28:35.746-04:00">INTERIM</status_change>
            <status_change date="2011-11-21T04:13:14.246-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for vulnerable Windows SP4 and gdi32.dll version">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="gdi32.dll version is less than 5.0.2195.7205" test_ref="oval:org.mitre.oval:tst:9222"/>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable Windows XP SP2(x86) and gdi32.dll version">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="gdi32.dll version is less than 5.1.2600.3466" test_ref="oval:org.mitre.oval:tst:8575"/>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable Windows XP SP3(x86) and gdi32.dll version">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="gdi32.dll version is less than 5.1.2600.5698" test_ref="oval:org.mitre.oval:tst:8610"/>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable Windows 2003 SP1(x86)/(x64)/(ia-64)/XP SP1(x64) and gdi32.dll version">
          <criteria operator="OR" comment="Check for vulnerable Windows 2003 SP1(x86)/(x64)/(ia-64)/XP SP1(x64)">
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:4386"/>
            <extend_definition comment="Microsoft Windows XP Professional x64 Edition SP1 is installed" definition_ref="oval:org.mitre.oval:def:720"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
          </criteria>
          <criterion comment="gdi32.dll version is less than 5.2.3790.3233" test_ref="oval:org.mitre.oval:tst:9298"/>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable Windows 2003 SP2(x86)/(x64)/(ia-64)/XP SP2(x64) and gdi32.dll version">
          <criteria operator="OR" comment="Check for vulnerable Windows 2003 SP2(x86)/(x64)/(ia-64)/XP SP2(x64)">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="gdi32.dll version is less than 5.2.3790.4396" test_ref="oval:org.mitre.oval:tst:9467"/>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable Windows Vista and gdi32.dll version">
          <criteria operator="OR" comment="Check for vulnerable Windows Vista">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criterion comment="Check if version of Gdi32.dll is less than 6.0.6000.16766" test_ref="oval:org.mitre.oval:tst:75175"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if version of Gdi32.dll is greater than or equal to 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:75193"/>
              <criterion comment="Check if version of Gdi32.dll is less than 6.0.6000.20940" test_ref="oval:org.mitre.oval:tst:74784"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for Vulnerable Windows Vista(x86)/(x64)/Server 2008(x86)/(x64)/(ia-64) and gdi32.dll version">
          <criteria operator="OR" comment="Check for Vulnerable Windows Vista(x86)/(x64)/Server 2008(x86)/(x64)/(ia-64)">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criterion comment="gdi32.dll version is less than 6.0.6001.18159" test_ref="oval:org.mitre.oval:tst:9510"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if version of Gdi32.dll is greater than or equal to 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:74690"/>
              <criterion comment="Check if version of Gdi32.dll is less than 6.0.6001.22291" test_ref="oval:org.mitre.oval:tst:75205"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6048" version="4" class="vulnerability">
      <metadata>
        <title>IE v5.01, SP4 HijackClick 3 / Script in Image Tag File Download Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0841" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0841"/>
        <description>Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" and the "Script in Image Tag File Download Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-01-20T02:31:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed ste:2614: set datatype to version.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:54:00.319-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:59:45.715-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:48.581-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:36.497-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:24.192-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3534.2800" negate="false" test_ref="oval:org.mitre.oval:tst:519"/>
          <criterion comment="the patch kb834707-ie501sp4 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:518"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6045" version="3" class="vulnerability">
      <metadata>
        <title>Windows Kernel Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2252" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2252"/>
        <description>The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate parameters sent from user mode to the kernel, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-10-14T13:33:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-10-16T14:01:53.438-04:00">DRAFT</status_change>
            <status_change date="2008-11-03T04:00:25.016-05:00">INTERIM</status_change>
            <status_change date="2008-11-24T04:00:20.448-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6045 - def:5902, def:6010 and def:6045 are updated with LDR inclusion" date="2011-10-28T20:15:00.324-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2011-10-28T20:33:45.272-04:00">INTERIM</status_change>
            <status_change date="2011-11-14T04:00:56.112-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="windows 2000 sp4/version">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Win32k.sys version is less than 5.0.2195.7194" test_ref="oval:org.mitre.oval:tst:9225"/>
        </criteria>
        <criteria operator="AND" comment="win xp sp2(32 bit)/version">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="Win32k.sys version is less than 5.1.2600.3446" test_ref="oval:org.mitre.oval:tst:8612"/>
        </criteria>
        <criteria operator="AND" comment="win xp sp3(32 bit)/version">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Win32k.sys version is less than 5.1.2600.5676" test_ref="oval:org.mitre.oval:tst:9293"/>
        </criteria>
        <criteria operator="AND" comment="server 2003sp1(32/64/ia-64)/win xp professional 64/version">
          <criteria operator="OR" comment="server 2003 sp1(32/64/ia-64)/win xp professional 64">
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:4386"/>
            <extend_definition comment="Microsoft Windows XP Professional x64 Edition SP1 is installed" definition_ref="oval:org.mitre.oval:def:720"/>
          </criteria>
          <criterion comment="Win32k.sys version is less than 5.2.3790.3212" test_ref="oval:org.mitre.oval:tst:9353"/>
        </criteria>
        <criteria operator="AND" comment="server 2003sp2 (32/64/ia-64)/win xp sp2 professional 64)/version">
          <criteria operator="OR" comment="server 2003sp2 (32/64/ia-64)/win xp sp2 professional 64">
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          </criteria>
          <criterion comment="Win32k.sys version is less than 5.2.3790.4375" test_ref="oval:org.mitre.oval:tst:9112"/>
        </criteria>
        <criteria operator="AND" comment="vista/server 2008(32/64)/version">
          <criteria operator="OR" comment="vista/server 2008(32/64)">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="GDR/LDR">
            <criterion comment="Win32k.sys version is less than 6.0.6000.16750" test_ref="oval:org.mitre.oval:tst:8810"/>
            <criteria operator="AND" comment="LDR range">
              <criterion comment="Check if the version of Win32k.sys is less than 6.0.6000.20917" test_ref="oval:org.mitre.oval:tst:43564"/>
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:44402"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="vista sp1(32/64)/server 2008 ia-64/version">
          <criteria operator="OR" comment="vista sp1(32/64)/server 2008 ia-64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criteria operator="OR" comment="GDR/LDR">
            <criterion comment="Win32k.sys version is less than 6.0.6001.18141" test_ref="oval:org.mitre.oval:tst:8928"/>
            <criteria operator="AND" comment="LDR range">
              <criterion comment="Check if the version of Win32k.sys is less than 6.0.6001.22265" test_ref="oval:org.mitre.oval:tst:44031"/>
              <criterion comment="the version of win32k.sys is greater than or equal to 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:43082"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6044" version="1" class="vulnerability">
      <metadata>
        <title>SMB Validation Denial of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4114" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4114"/>
        <description>srv.sys in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to cause a denial of service (system crash) or possibly have unspecified other impact via an SMB WRITE_ANDX packet with an offset that is inconsistent with the packet size, related to "insufficiently validating the buffer size," as demonstrated by a request to the \PIPE\lsarpc named pipe, aka "SMB Validation Denial of Service Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-01-13T13:07:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2009-01-20T17:42:23.952-05:00">DRAFT</status_change>
            <modified comment="In testing I found that the GDR file versions for Vista SP1 could be exactly 6.0.6001.18000.  changed all of the GDR/LDR lower bound file version tests to require greater than or equal instead of  strictly greater than." date="2009-01-30T18:02:00.330-05:00">
              <contributor organization="National Institute of Standards and Technology">Timothy Harrison</contributor>
            </modified>
            <status_change date="2009-02-16T04:00:25.274-05:00">INTERIM</status_change>
            <status_change date="2009-03-09T04:00:09.929-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Srv.sys version is less than 5.0.2195.7222" test_ref="oval:org.mitre.oval:tst:9419"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="Srv.sys version is less than 5.1.2600.3491" test_ref="oval:org.mitre.oval:tst:9449"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Srv.sys version is less than 5.1.2600.5725" test_ref="oval:org.mitre.oval:tst:9588"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="Srv.sys version is less than 5.2.3790.3260" test_ref="oval:org.mitre.oval:tst:9297"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <criterion comment="Srv.sys version is less than 5.2.3790.4425" test_ref="oval:org.mitre.oval:tst:9603"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:4386"/>
            <extend_definition comment="Microsoft Windows XP x64 Edition SP1 is installed" definition_ref="oval:org.mitre.oval:def:720"/>
          </criteria>
          <criterion comment="Srv.sys version is less than 5.2.3790.3260" test_ref="oval:org.mitre.oval:tst:9297"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          </criteria>
          <criterion comment="Srv.sys version is less than 5.2.3790.4425" test_ref="oval:org.mitre.oval:tst:9603"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9543"/>
          <criterion comment="Srv.sys version is less than 6.0.6000.16789" test_ref="oval:org.mitre.oval:tst:9450"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:8674"/>
          <criterion comment="Srv.sys version is less than 6.0.6000.20976" test_ref="oval:org.mitre.oval:tst:8697"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9601"/>
          <criterion comment="Srv.sys version is less than 6.0.6001.18185" test_ref="oval:org.mitre.oval:tst:9369"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9666"/>
          <criterion comment="Srv.sys version is less than 6.0.6001.22331" test_ref="oval:org.mitre.oval:tst:8713"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9543"/>
          <criterion comment="Srv.sys version is less than 6.0.6000.16789" test_ref="oval:org.mitre.oval:tst:9450"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:8674"/>
          <criterion comment="Srv.sys version is less than 6.0.6000.20976" test_ref="oval:org.mitre.oval:tst:8697"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9601"/>
          <criterion comment="Srv.sys version is less than 6.0.6001.18185" test_ref="oval:org.mitre.oval:tst:9369"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9666"/>
          <criterion comment="Srv.sys version is less than 6.0.6001.22331" test_ref="oval:org.mitre.oval:tst:8713"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6042" version="1" class="vulnerability">
      <metadata>
        <title>Memory Corruption in Indexing Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2507" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2507"/>
        <description>A certain ActiveX control in the Indexing Service in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly process URLs, which allows remote attackers to execute arbitrary programs via unspecified vectors that cause a "vulnerable binary" to load and run, aka "Memory Corruption in Indexing Service Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-13T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-10-22T17:36:45.516-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:33.465-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:18.262-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of query.dll is less than 5.0.2195.7320" test_ref="oval:org.mitre.oval:tst:10734"/>
        </criteria>
        <criteria operator="AND" comment="Windows XP x86 SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="the version of query.dll is less than 5.1.2600.3602" test_ref="oval:org.mitre.oval:tst:10632"/>
        </criteria>
        <criteria operator="AND" comment="Windows XP x86 SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of query.dll is less than 5.1.2600.5847" test_ref="oval:org.mitre.oval:tst:10993"/>
        </criteria>
        <criteria operator="AND" comment="Windows XP x64 SP2, Windows Server 2003 SP2 x86/x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of query.dll is less than 5.2.3790.4554" test_ref="oval:org.mitre.oval:tst:10897"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6041" version="7" class="vulnerability">
      <metadata>
        <title>Race Condition Cross-Domain Information Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3091" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3091"/>
        <description>Race condition in Microsoft Internet Explorer 6 SP1; 6 and 7 for Windows XP SP2 and SP3; 6 and 7 for Server 2003 SP2; 7 for Vista Gold, SP1, and SP2; and 7 for Server 2008 SP2 allows remote attackers to execute arbitrary code or perform other actions upon a page transition, with the permissions of the old page and the content of the new page, as demonstrated by setInterval functions that set location.href within a try/catch expression, aka the "bait &amp; switch vulnerability" or "Race Condition Cross-Domain Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-06-09T14:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-06-15T17:06:41.400-04:00">DRAFT</status_change>
            <status_change date="2009-07-06T04:00:34.731-04:00">INTERIM</status_change>
            <status_change date="2009-07-21T07:46:00.104-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6041 - Modified GDR/LDR service branch format to read easier, removed duplicate, and updated extended def for Vista." date="2011-01-31T14:15:00.599-05:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-01-31T14:15:35.708-05:00">INTERIM</status_change>
            <status_change date="2011-02-21T04:00:56.485-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:25:12.145-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:12.751-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6041 - extended definitions of OS are without SP checks" date="2014-07-28T17:41:00.906-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:42:51.829-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:08.099-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 6 on Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1627" test_ref="oval:org.mitre.oval:tst:9757"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on Windows XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3562" test_ref="oval:org.mitre.oval:tst:9989"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on Windows XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5803" test_ref="oval:org.mitre.oval:tst:10078"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on all Windows XP x64, Server 2003 x86,x64,ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4504" test_ref="oval:org.mitre.oval:tst:9507"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows XP x86, x64">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16850" test_ref="oval:org.mitre.oval:tst:10212"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.21045" test_ref="oval:org.mitre.oval:tst:10207"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16850" test_ref="oval:org.mitre.oval:tst:10212"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.21045" test_ref="oval:org.mitre.oval:tst:10207"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16851" test_ref="oval:org.mitre.oval:tst:9914"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.21046" test_ref="oval:org.mitre.oval:tst:10068"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows Vista x86/x64, all Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6001.18248" test_ref="oval:org.mitre.oval:tst:9929"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6001.22418" test_ref="oval:org.mitre.oval:tst:9978"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows Vista x86/x64, Server 2008 x86/64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6002.18024" test_ref="oval:org.mitre.oval:tst:9840"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6002.22121" test_ref="oval:org.mitre.oval:tst:10061"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6036" version="5" class="vulnerability">
      <metadata>
        <title>Windows Kernel Handle Validation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0082" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0082"/>
        <description>The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate handles, which allows local users to gain privileges via a crafted application that triggers unspecified "actions," aka "Windows Kernel Handle Validation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-03-10T16:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-03-13T20:23:58.798-04:00">DRAFT</status_change>
            <status_change date="2009-03-30T04:00:21.956-04:00">INTERIM</status_change>
            <status_change date="2009-04-20T04:00:20.039-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6036 - Updated LDR criteria for Win-Vista &amp; Win-2008." date="2011-10-03T15:38:00.951-04:00">
              <contributor organization="SecPod Technologies">Pradeep R B</contributor>
            </modified>
            <status_change date="2011-10-03T15:39:55.108-04:00">INTERIM</status_change>
            <status_change date="2011-10-24T04:00:18.373-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4525 - contains tests with modified comments and all dependences" date="2014-02-13T12:19:00.287-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:23:14.941-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:12.477-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for Microsoft Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of win32k.sys is less than 5.0.2195.7251" test_ref="oval:org.mitre.oval:tst:8764"/>
        </criteria>
        <criteria operator="AND" comment="Check for Microsoft Windows XP (x86) SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="the version of win32k.sys is less than 5.1.2600.3521" test_ref="oval:org.mitre.oval:tst:9733"/>
        </criteria>
        <criteria operator="AND" comment="Check for Microsoft Windows XP (x86) SP3">
          <criterion comment="the version of win32k.sys is less than 5.1.2600.5756" test_ref="oval:org.mitre.oval:tst:9386"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
        </criteria>
        <criteria operator="AND" comment="Check for Windows Server 2003 (ia64) SP1/Windows Server 2003 SP1 (x86)/Windows Server 2003 SP1 (x64)/Windows XP Professional x64 Edition">
          <criteria operator="OR" comment="Windows Server 2003 (ia64) SP1/Windows Server 2003 SP1 (x86)/Windows Server 2003 SP1 (x64)/Windows XP Professional x64 Edition">
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:4386"/>
            <extend_definition comment="Microsoft Windows XP Professional x64 Edition SP1 is installed" definition_ref="oval:org.mitre.oval:def:720"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
          </criteria>
          <criterion comment="the version of win32k.sys is less than 5.2.3790.3291" test_ref="oval:org.mitre.oval:tst:9426"/>
        </criteria>
        <criteria operator="AND" comment="Check for Windows Server 2003 (ia64) SP2/Windows Server 2003 SP2 (x64)/Windows XP x64 Edition SP2/Windows Server 2003 SP2 (x86)">
          <criteria operator="OR" comment="Windows Server 2003 (ia64) SP2/Windows Server 2003 SP2 (x64)/Windows XP x64 Edition SP2/Windows Server 2003 SP2 (x86)">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of win32k.sys is less than 5.2.3790.4456" test_ref="oval:org.mitre.oval:tst:8835"/>
        </criteria>
        <criteria operator="AND" comment="Check for Windows Vista x64 Edition/Microsoft Windows Vista (32-bit)">
          <criteria operator="OR" comment="Windows Vista x64 Edition/Microsoft Windows Vista (32-bit)">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criterion comment="the version of win32k.sys is less than 6.0.6000.16816" test_ref="oval:org.mitre.oval:tst:9608"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="the version of win32k.sys is greater than 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9977"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6000.21006" test_ref="oval:org.mitre.oval:tst:44149"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for Windows Vista x64 Edition Service Pack 1/Windows Server 2008 (64-bit)/Windows Server 2008 (ia-64)/Microsoft Windows Vista (32-bit)/Microsoft Windows Server 2008 (32-bit) Service Pack 1">
          <criteria operator="OR" comment="Windows Vista x64 Edition Service Pack 1/Windows Server 2008 (64-bit)/Windows Server 2008 (ia-64)/Microsoft Windows Vista (32-bit)/Microsoft Windows Server 2008 (32-bit) Service Pack 1">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criterion comment="the version of win32k.sys is less than 6.0.6001.18211" test_ref="oval:org.mitre.oval:tst:8799"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="the version of win32k.sys is greater than 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:10142"/>
              <criterion comment="Check if version of win32k.sys is less than 6.0.6001.22372" test_ref="oval:org.mitre.oval:tst:43675"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6031" version="4" class="vulnerability">
      <metadata>
        <title>IE v5.5, SP2 HijackClick 3 / Script in Image Tag File Download Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0841" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0841"/>
        <description>Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" and the "Script in Image Tag File Download Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-25T07:54:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-27T01:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-17T10:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:42:00.000-04:00" comment="modified wft-562 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:38.043-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:24.130-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
          <criterion comment="the version of mshtml.dll is less than 5.50.4945.2800" negate="false" test_ref="oval:org.mitre.oval:tst:384"/>
          <criterion comment="the patch kb834707 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:855"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6027" version="6" class="vulnerability">
      <metadata>
        <title>Windows HTTP Services Certificate Name Mismatch Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0089" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0089"/>
        <description>Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, and Vista Gold allows remote web servers to impersonate arbitrary https web sites by using DNS spoofing to "forward a connection" to a different https web site that has a valid certificate matching its own domain name, but not a certificate matching the domain name of the host requested by the user, aka "Windows HTTP Services Certificate Name Mismatch Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-04-14T16:00:00">
              <contributor organization="Gideon Technologies, Inc.">Kyle Key</contributor>
            </submitted>
            <status_change date="2009-04-17T16:45:14.167-04:00">DRAFT</status_change>
            <status_change date="2009-05-04T04:00:26.586-04:00">INTERIM</status_change>
            <status_change date="2009-05-25T04:01:53.877-04:00">ACCEPTED</status_change>
            <modified comment="Removed CVE from title. Removed Microsoft reference" date="2009-06-01T16:05:28.035-04:00">
              <contributor organization="The MITRE Corporation">Brendan Miles</contributor>
            </modified>
            <status_change date="2009-06-08T04:00:53.875-04:00">INTERIM</status_change>
            <status_change date="2009-06-29T04:00:48.766-04:00">ACCEPTED</status_change>
            <modified comment="Edited var:306 - Added beginning anchor to local_variable used in pattern match" date="2010-05-13T15:50:00.065-04:00">
              <contributor organization="The MITRE Corporation">Mike Lah</contributor>
            </modified>
            <status_change date="2010-05-13T15:50:58.886-04:00">INTERIM</status_change>
            <status_change date="2010-05-31T04:00:13.657-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:306 - Added closing anchors for variable regex" date="2013-04-08T11:01:00.574-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2013-04-08T11:03:33.727-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:17:38.036-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="winhttp.dll version 5.1.2600.3490 or later on Windows 2000 sp4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="system32\winhttp.dll version less than 5.1.2600.3490" test_ref="oval:org.mitre.oval:tst:9822"/>
        </criteria>
        <criteria operator="AND" comment="winhttp.dll versin 5.1.2600.3494 or later on windows xp sp2 x86">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="system32\winhttp.dll version less than 5.1.2600.3494" test_ref="oval:org.mitre.oval:tst:9877"/>
        </criteria>
        <criteria operator="AND" comment="winhttp.dll versin 5.1.2600.5727 or later on windows xp sp3 x86">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="system32\winhttp.dll version less than 5.1.2600.5727" test_ref="oval:org.mitre.oval:tst:9540"/>
        </criteria>
        <criteria operator="AND" comment="winhttp.dll versin 5.2.3790.3262 or later on windows xp sp1 x64">
          <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="system32\winhttp.dll version less than 5.2.3790.3262" test_ref="oval:org.mitre.oval:tst:9795"/>
        </criteria>
        <criteria operator="AND" comment="winhttp.dll versin 5.2.3790.4427 or later on windows xp sp2 x64">
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          <criterion comment="system32\winhttp.dll version less than 5.2.3790.4427" test_ref="oval:org.mitre.oval:tst:9649"/>
        </criteria>
        <criteria operator="AND" comment="winhttp.dll versin 5.2.3790.3262 or later on windows server 2003 sp1 (x86)(x64)(ia64)">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:4386"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP1 is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
          </criteria>
          <criterion comment="Winsxs\winhttp.dll version less than 5.2.3790.3262" test_ref="oval:org.mitre.oval:tst:9580"/>
        </criteria>
        <criteria operator="AND" comment="winhttp.dll versin 5.2.3790.4427 or later on windows server 2003 sp2 (x86)(x64)(ia64)">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="Winsxs\winhttp.dll version less than 5.2.3790.4427" test_ref="oval:org.mitre.oval:tst:9985"/>
        </criteria>
        <criteria operator="AND" comment="winhttp.dll versin 6.0.6000.16786 or later on windows vista GDR (x86)(x64)">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="system32\winhttp.dll version greater than or equal 6.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9951"/>
          <criterion comment="system32\winhttp.dll version less than 6.0.6000.16786" test_ref="oval:org.mitre.oval:tst:9981"/>
        </criteria>
        <criteria operator="AND" comment="winhttp.dll versin 6.0.6000.20971 or later on windows vista LDR (x86)(x64)">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="system32\winhttp.dll version greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9442"/>
          <criterion comment="system32\winhttp.dll version less than 6.0.6000.20971" test_ref="oval:org.mitre.oval:tst:9594"/>
        </criteria>
        <criteria operator="AND" comment="winhttp.dll versin 6.0.6001.18178 or later on windows server 2008 sp1 GDR (x86)(x64)(ia64) and windows vista sp1 GDR (x86)(x64)">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
          </criteria>
          <criterion comment="system32\winhttp.dll version greater than or equal 6.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9762"/>
          <criterion comment="system32\winhttp.dll version less than 6.0.6001.18178" test_ref="oval:org.mitre.oval:tst:9801"/>
        </criteria>
        <criteria operator="AND" comment="winhttp.dll versin 6.0.6001.22323 or later on windows server 2008 sp1 LDR (x86)(x64)(ia64) and windows vista sp1 GDR (x86)(x64)">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
          </criteria>
          <criterion comment="system32\winhttp.dll version greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9825"/>
          <criterion comment="system32\winhttp.dll version less than 6.0.6001.22323" test_ref="oval:org.mitre.oval:tst:9119"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6025" version="5" class="vulnerability">
      <metadata>
        <title>HTML Objects Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2258" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2258"/>
        <description>Microsoft Internet Explorer 5.01, 6, and 7 accesses uninitialized memory in certain conditions, which allows remote attackers to cause a denial of service (crash) and execute arbitrary code via vectors related to a document object "appended in a specific order" with "particular functions ... performed on" document objects, aka "HTML Objects Memory Corruption Vulnerability" or "Table Layout Memory Corruption Vulnerability," a different vulnerability than CVE-2008-2257.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-13T09:28:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-08-14T15:02:29.725-04:00">DRAFT</status_change>
            <modified comment="Replaced CVE-2008-2257 with CVE-2008-2258" date="2008-08-26T10:42:00.546-04:00">
              <contributor organization="Secure Elements, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2008-09-15T04:00:27.219-04:00">INTERIM</status_change>
            <status_change date="2008-10-06T04:00:17.082-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6025 - Included LDR support &amp; added new state to match correct version." date="2011-10-25T14:07:00.717-04:00">
              <contributor organization="SecPod Technologies">Pooja Shetty</contributor>
            </modified>
            <status_change date="2011-10-25T14:11:55.976-04:00">INTERIM</status_change>
            <status_change date="2011-11-14T04:00:55.270-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6025 - extended definitions of OS are without SP checks" date="2014-07-28T17:41:00.906-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:42:54.354-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:07.818-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win 2K + IE6 vulnerable version">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1613" test_ref="oval:org.mitre.oval:tst:8781"/>
        </criteria>
        <criteria operator="AND" comment="Win 2K + IE 5.01">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="Mshtml.dll version is less than 5.0.3866.2000" test_ref="oval:org.mitre.oval:tst:8949"/>
        </criteria>
        <criteria operator="AND" comment="Win XP + IE 6">
          <extend_definition comment="Microsoft Windows XP is installed" definition_ref="oval:org.mitre.oval:def:105"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3395" test_ref="oval:org.mitre.oval:tst:8921"/>
        </criteria>
        <criteria operator="AND" comment="Win XP + IE 6">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5626" test_ref="oval:org.mitre.oval:tst:9128"/>
        </criteria>
        <criteria operator="AND" comment="Win XP /  Win 2K3 + IE 7">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="Win XP / Win 2K3">
            <extend_definition comment="Microsoft Windows XP is installed" definition_ref="oval:org.mitre.oval:def:105"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR / GDR">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16705" test_ref="oval:org.mitre.oval:tst:9018"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Check if the version mshtml.dll is less than 7.0.6000.20861" test_ref="oval:org.mitre.oval:tst:44137"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 2K3 / Win XP X64 and IE 6">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.3167" test_ref="oval:org.mitre.oval:tst:8958"/>
          <criteria operator="OR" comment="Win 2K3 / Win XP X64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win XP X64 / Win 2K3">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4324" test_ref="oval:org.mitre.oval:tst:8988"/>
          <criteria operator="OR" comment="Win 2K3 / Win XP X64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win Vista and IE7">
          <extend_definition comment="Microsoft Windows Vista is installed" definition_ref="oval:org.mitre.oval:def:228"/>
          <criteria operator="OR" comment="Check for LDR and GDR">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16711" test_ref="oval:org.mitre.oval:tst:8163"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.20868" test_ref="oval:org.mitre.oval:tst:44258"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
        </criteria>
        <criteria operator="AND" comment="Win Vista / Win 2K8 and IE7">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="Win Vista/ Win 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR /GDR">
            <criterion comment="Mshtml.dll version is less than 7.0.6001.18099" test_ref="oval:org.mitre.oval:tst:9108"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Mshtml.dll version is greater than or equal to 7.0.6001.22000" test_ref="oval:org.mitre.oval:tst:42152"/>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6001.22212" test_ref="oval:org.mitre.oval:tst:44416"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6024" version="3" class="vulnerability">
      <metadata>
        <title>Avast! Home and Professional 'aavmKer4.sys' Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Avast! AntiVirus</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3523" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3523"/>
        <description>aavmKer4.sys in avast! Home and Professional for Windows before 4.8.1356 does not properly validate input to IOCTLs (1) 0xb2d6000c and (2) 0xb2d60034, which allows local users to gain privileges via IOCTL requests using crafted kernel addresses that trigger memory corruption, a different vulnerability than CVE-2008-1625.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-25T10:27:31.430-04:00">
              <contributor organization="SecPod Technologies">Sharath S</contributor>
            </submitted>
            <status_change date="2009-11-25T13:47:36.986-05:00">DRAFT</status_change>
            <status_change date="2009-12-14T04:00:07.702-05:00">INTERIM</status_change>
            <status_change date="2010-01-04T04:01:41.807-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:592 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:27:16.835-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:12.702-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Avast! AntiVirus is installed" definition_ref="oval:org.mitre.oval:def:6558"/>
        <criterion comment="Avast! version is less than 4.8.1356.0" test_ref="oval:org.mitre.oval:tst:10746"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6558" version="5" class="inventory">
      <metadata>
        <title>Avast! AntiVirus for Windows is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Avast! AntiVirus</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:avast:avast_antivirus:::windows"/>
        <description>The application Avast! AntiVirus for Windows is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-25T10:27:37">
              <contributor organization="SecPod Technologies">Sharath S</contributor>
            </submitted>
            <status_change date="2009-11-25T13:47:36.546-05:00">DRAFT</status_change>
            <status_change date="2009-12-14T04:00:15.773-05:00">INTERIM</status_change>
            <status_change date="2010-01-04T04:01:53.587-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6558 - Modifications vary from minor OVAL title/description changes to suggesting an alternative CPE name to use." date="2011-09-28T11:29:00.976-04:00">
              <contributor organization="The MITRE Corporation">David Rothenberg</contributor>
            </modified>
            <status_change date="2011-09-28T11:33:35.733-04:00">INTERIM</status_change>
            <status_change date="2011-10-17T04:00:23.746-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:10161 - def:6558 - platform list updated, extended definitions removed, new tests for Avast" date="2014-03-26T13:20:00.160-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-26T13:22:02.443-04:00">INTERIM</status_change>
            <status_change date="2014-04-14T04:00:18.046-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Avast! AntiVirus old version is installed" test_ref="oval:org.mitre.oval:tst:10161"/>
        <criterion comment="Avast! AntiVirus is installed" test_ref="oval:org.mitre.oval:tst:113006"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6016" version="1" class="vulnerability">
      <metadata>
        <title>Windows Desktop Parameter Edit Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1126" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1126"/>
        <description>The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly validate the user-mode input associated with the editing of an unspecified desktop parameter, which allows local users to gain privileges via a crafted application, aka "Windows Desktop Parameter Edit Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-06-09T14:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-06-15T17:07:27.216-04:00">DRAFT</status_change>
            <status_change date="2009-07-06T04:00:33.211-04:00">INTERIM</status_change>
            <status_change date="2009-07-21T07:45:59.265-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of win32k.sys is less than 5.0.2195.7279" test_ref="oval:org.mitre.oval:tst:10057"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="the version of win32k.sys is less than 5.1.2600.3556" test_ref="oval:org.mitre.oval:tst:10075"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of win32k.sys is less than 5.1.2600.5796" test_ref="oval:org.mitre.oval:tst:9735"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of win32k.sys is less than 5.2.3790.4497" test_ref="oval:org.mitre.oval:tst:9867"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6012" version="6" class="vulnerability">
      <metadata>
        <title>SMB Credential Reflection Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4037" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4037"/>
        <description>Microsoft Windows 2000 Gold through SP4, XP Gold through SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote SMB servers to execute arbitrary code on a client machine by replaying the NTLM credentials of a client user, as demonstrated by backrush, aka "SMB Credential Reflection Vulnerability."  NOTE: some reliable sources report that this vulnerability exists because of an insufficient fix for CVE-2000-0834.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-11-19T14:19:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-11-19T10:55:27.254-05:00">DRAFT</status_change>
            <status_change date="2008-12-08T04:01:05.623-05:00">INTERIM</status_change>
            <status_change date="2008-12-29T04:00:35.154-05:00">ACCEPTED</status_change>
            <modified comment="Updated comment to be consistent with test" date="2010-02-10T12:57:00.636-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2010-02-10T12:58:38.938-05:00">INTERIM</status_change>
            <modified comment="Updated comment to be consistent with test" date="2010-02-10T12:59:00.665-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <modified comment="Updated comment to be consistent with test" date="2010-02-10T12:59:00.585-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <modified comment="Updated comment to be consistent with test" date="2010-02-10T12:59:00.822-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <modified comment="Changed operation attribute to 'greater than or equals'" date="2010-02-10T13:00:00.223-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <modified comment="Changed operation attribute to 'greater than or equals'" date="2010-02-10T13:05:00.805-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <modified comment="Changed operation attribute to 'greater than or equals'" date="2010-02-10T13:05:00.517-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <modified comment="Changed operation attribute to 'greater than or equals'" date="2010-02-10T13:05:00.923-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2010-03-01T04:00:05.708-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6012 - &quot;Added support for Windows Server 2003 SP1 &amp; SP2 for Itanium Edition&quot; and &quot;Removed test criterion tst:9035 &amp; tst:9505, which wasn't required.&quot;" date="2011-10-17T14:48:00.683-04:00">
              <contributor organization="SecPod Technologies">Prashanth A.</contributor>
            </modified>
            <status_change date="2011-10-17T14:50:56.329-04:00">INTERIM</status_change>
            <status_change date="2011-11-07T04:01:03.883-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4525 - contains tests with modified comments and all dependences" date="2014-02-13T12:19:00.287-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:23:14.170-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:12.165-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for Vulnerable Windows 2000 SP4 and Mrxsmb.sys version">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Mrxsmb.sys version is less than 5.0.2195.7174" test_ref="oval:org.mitre.oval:tst:9360"/>
        </criteria>
        <criteria operator="AND" comment="Check for Vulnerable Windows XP (x86) SP2 and Mrxsmb.sys version">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="Mrxsmb.sys version is less than 5.1.2600.3467" test_ref="oval:org.mitre.oval:tst:8573"/>
        </criteria>
        <criteria operator="AND" comment="Check for Vulnerable Windows XP (x86) SP3 and Mrxsmb.sys version">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Mrxsmb.sys version is less than 5.1.2600.5700" test_ref="oval:org.mitre.oval:tst:9308"/>
        </criteria>
        <criteria operator="AND" comment="Check for Vulnerable Windows Server 2003 SP1 (x64)/(x86)/(ia-64)/Windows XP Professional SP1 (x64) and Mrxsmb.sys version">
          <criteria operator="OR" comment="Check for Vulnerable Windows Server 2003 SP1 (x64)/(x86)/(ia-64)/Windows XP Professional SP1 (x64)">
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:4386"/>
            <extend_definition comment="Microsoft Windows XP Professional x64 Edition SP1 is installed" definition_ref="oval:org.mitre.oval:def:720"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
          </criteria>
          <criterion comment="Mrxsmb.sys version is less than 5.2.3790.3206" test_ref="oval:org.mitre.oval:tst:9180"/>
        </criteria>
        <criteria operator="AND" comment="Check for Vulnerable Windows Server 2003 SP2 (x64)/(x86)/(ia-64)Windows XP Professional SP2 (x64)and Mrxsmb.sys version">
          <criteria operator="OR" comment="Check for Vulnerable Windows Server 2003 SP2 (x64)/(x86)/(ia-64)/Windows XP Professional SP2 (x64)">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="Mrxsmb.sys version is less than 5.2.3790.4369" test_ref="oval:org.mitre.oval:tst:9476"/>
        </criteria>
        <criteria operator="AND" comment="Check for Vulnerable Windows Vista(x64)/Vista(x86) and Mrxsmb10.sys version">
          <criteria operator="OR" comment="Check for Vulnerable Windows Vista(x64)/Vista(x86)">
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criteria operator="AND" comment="Check for GDR">
              <criterion comment="Mrxsmb10.sys version is less than 6.0.6000.16738" test_ref="oval:org.mitre.oval:tst:9295"/>
            </criteria>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Mrxsmb10.sys version is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9423"/>
              <criterion comment="Mrxsmb10.sys version is less than 6.0.6000.20904" test_ref="oval:org.mitre.oval:tst:9374"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for Vulnerable Windows Vista (32-bit)SP1/x64 SP1/Server 2008 (32-bit)/(64-bit)/(ia-64) and Mrxsmb10.sys version">
          <criteria operator="OR" comment="Check for Vulnerable Windows Vista (32-bit)SP1/x64 SP1/Server 2008 (32-bit)/(64-bit)/(ia-64)">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criteria operator="AND" comment="Check for GDR">
              <criterion comment="Mrxsmb10.sys version is less than 6.0.6001.18130" test_ref="oval:org.mitre.oval:tst:8808"/>
            </criteria>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Mrxsmb10.sys version is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9535"/>
              <criterion comment="Mrxsmb10.sys version is less than 6.0.6001.22252" test_ref="oval:org.mitre.oval:tst:9477"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6011" version="3" class="vulnerability">
      <metadata>
        <title>SChannel Spoofing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0085" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0085"/>
        <description>The Secure Channel (aka SChannel) authentication component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008, when certificate authentication is used, does not properly validate the client's key exchange data in Transport Layer Security (TLS) handshake messages, which allows remote attackers to spoof authentication by crafting a TLS packet based on knowledge of the certificate but not the private key, aka "SChannel Spoofing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-03-10T16:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-03-13T20:24:00.338-04:00">DRAFT</status_change>
            <status_change date="2009-03-30T04:00:20.311-04:00">INTERIM</status_change>
            <status_change date="2009-04-20T04:00:18.909-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6011 - LDR version criteria are added for Vista &amp; 2008, and also added non-root criterion comments" date="2011-10-04T13:14:00.818-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-10-04T13:16:11.404-04:00">INTERIM</status_change>
            <status_change date="2011-10-24T04:00:17.494-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Microsoft Windows 2000 SP4 is installed and schannel.dll file version">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of schannel.dll is less than 5.1.2195.7213" test_ref="oval:org.mitre.oval:tst:9387"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Windows XP (x86) SP2 is installed and schannel.dll file version">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="the version of schannel.dll is less than 5.1.2600.3487" test_ref="oval:org.mitre.oval:tst:9506"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Windows XP (x86) SP3 is installed and schannel.dll file version">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of schannel.dll is less than 5.1.2600.5721" test_ref="oval:org.mitre.oval:tst:9556"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Windows XP x64/Windows server 2003 (x86/x64/ia64) SP1 is installed and schannel.dll file version">
          <criteria operator="OR" comment="Microsoft Windows XP x64/Microsoft Windows server 2003 (x86/x64/ia64) SP1 is installed">
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:4386"/>
            <extend_definition comment="Microsoft Windows XP Professional x64 Edition SP1 is installed" definition_ref="oval:org.mitre.oval:def:720"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
          </criteria>
          <criterion comment="the version of schannel.dll is less than 5.2.3790.3293" test_ref="oval:org.mitre.oval:tst:9584"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Windows XP x64/Windows server 2003 (x86/x64/ia64) SP2 is installed and schannel.dll file version">
          <criteria operator="OR" comment="Microsoft Windows XP x64/Windows server 2003 (x86/x64/ia64) SP2 is installed">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of schannel.dll is less than 5.2.3790.4458" test_ref="oval:org.mitre.oval:tst:9698"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Windows Vista (x86/x64) is installed and schannel.dll file version">
          <criteria operator="OR" comment="Microsoft Windows Vista (x86/x64) is installed">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="File version less than 6.0.6000.16782 or greater than or equal to 6.0.6000.20000 and less than 6.0.6000.20967">
            <criterion comment="the version of schannel.dll is less than 6.0.6000.16782" test_ref="oval:org.mitre.oval:tst:8794"/>
            <criteria operator="AND" comment="For LDR file version greater than or equal to 6.0.6000.20000 and less than 6.0.6000.20967">
              <criterion comment="the version of schannel.dll is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:43987"/>
              <criterion comment="the version of schannel.dll is less than 6.0.6000.20967" test_ref="oval:org.mitre.oval:tst:44127"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Microsoft Windows Vista (x86/x64) SP1 or Server 2008 (x86/x64/ia64) is installed and schannel.dll file version">
          <criteria operator="OR" comment="Microsoft Windows Vista (x86/x64) SP1 or Server 2008 (x86/x64/ia64) s installed">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="File version less than 6.0.6001.18175 or greater than equal to 6.0.6001.22000 and less than 6.0.6001.22320">
            <criterion comment="the version of schannel.dll is less than 6.0.6001.18175" test_ref="oval:org.mitre.oval:tst:9306"/>
            <criteria operator="AND" comment="For LDR file version greater than or equal to 6.0.6001.22000 and less than 6.0.6001.22320">
              <criterion comment="the version of schannel.dll is greater than or equal to 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:41291"/>
              <criterion comment="the version of schannel.dll is less than 6.0.6001.22320" test_ref="oval:org.mitre.oval:tst:43861"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6010" version="3" class="vulnerability">
      <metadata>
        <title>Windows Kernel Unhandled Exception Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2251" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2251"/>
        <description>Double free vulnerability in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows local users to gain privileges via a crafted application that makes system calls within multiple threads, aka "Windows Kernel Unhandled Exception Vulnerability." NOTE: according to Microsoft, this is not a duplicate of CVE-2008-4510.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-10-14T13:33:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-10-16T14:01:54.370-04:00">DRAFT</status_change>
            <status_change date="2008-11-03T04:00:23.791-05:00">INTERIM</status_change>
            <status_change date="2008-11-24T04:00:19.512-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6010 - def:5902, def:6010 and def:6045 are updated with LDR inclusion" date="2011-10-28T20:15:00.324-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2011-10-28T20:33:44.064-04:00">INTERIM</status_change>
            <status_change date="2011-11-14T04:00:54.510-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="windows 2000 sp4/version">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Win32k.sys version is less than 5.0.2195.7194" test_ref="oval:org.mitre.oval:tst:9225"/>
        </criteria>
        <criteria operator="AND" comment="win xp sp2(32 bit)/version">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="Win32k.sys version is less than 5.1.2600.3446" test_ref="oval:org.mitre.oval:tst:8612"/>
        </criteria>
        <criteria operator="AND" comment="win xp sp3(32 bit)/version">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Win32k.sys version is less than 5.1.2600.5676" test_ref="oval:org.mitre.oval:tst:9293"/>
        </criteria>
        <criteria operator="AND" comment="server 2003sp1(32/64/ia-64)/win xp professional 64/version">
          <criteria operator="OR" comment="server 2003 sp1(32/64/ia-64)/win xp professional 64">
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:4386"/>
            <extend_definition comment="Microsoft Windows XP Professional x64 Edition SP1 is installed" definition_ref="oval:org.mitre.oval:def:720"/>
          </criteria>
          <criterion comment="Win32k.sys version is less than 5.2.3790.3212" test_ref="oval:org.mitre.oval:tst:9353"/>
        </criteria>
        <criteria operator="AND" comment="server 2003sp2 (32/64/ia-64)/win xp sp2 professional 64)/version">
          <criteria operator="OR" comment="server 2003sp2 (32/64/ia-64)/win xp sp2 professional 64">
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          </criteria>
          <criterion comment="Win32k.sys version is less than 5.2.3790.4375" test_ref="oval:org.mitre.oval:tst:9112"/>
        </criteria>
        <criteria operator="AND" comment="vista/server 2008(32/64)/version">
          <criteria operator="OR" comment="vista/server 2008(32/64)">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="GDR/LDR">
            <criterion comment="Win32k.sys version is less than 6.0.6000.16750" test_ref="oval:org.mitre.oval:tst:8810"/>
            <criteria operator="AND" comment="LDR range">
              <criterion comment="Check if the version of Win32k.sys is less than 6.0.6000.20917" test_ref="oval:org.mitre.oval:tst:43564"/>
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:44402"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="vista sp1(32/64)/server 2008 ia-64/version">
          <criteria operator="OR" comment="vista sp1(32/64)/server 2008 ia-64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criteria operator="OR" comment="GDR/LDR">
            <criterion comment="Win32k.sys version is less than 6.0.6001.18141" test_ref="oval:org.mitre.oval:tst:8928"/>
            <criteria operator="AND" comment="LDR range">
              <criterion comment="Check if the version of Win32k.sys is less than 6.0.6001.22265" test_ref="oval:org.mitre.oval:tst:44031"/>
              <criterion comment="the version of win32k.sys is greater than or equal to 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:43082"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6007" version="6" class="vulnerability">
      <metadata>
        <title>Pointer Reference Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4844" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4844"/>
        <description>Use-after-free vulnerability in the CRecordInstance::TransferToDestination function in mshtml.dll in Microsoft Internet Explorer 5.01, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via DSO bindings involving (1) an XML Island, (2) XML DSOs, or (3) Tabular Data Control (TDC) in a crafted HTML or XML document, as demonstrated by nested SPAN or MARQUEE elements, and exploited in the wild in December 2008.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-02-10T16:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-02-13T17:01:58.846-05:00">DRAFT</status_change>
            <status_change date="2009-03-02T04:00:17.785-05:00">INTERIM</status_change>
            <status_change date="2009-03-23T04:00:15.541-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6007 - Added LDR versions check, Itanium &amp; XP 64 OS inclusion" date="2011-10-25T14:19:00.421-04:00">
              <contributor organization="SecPod Technologies">Pooja Shetty</contributor>
            </modified>
            <status_change date="2011-10-25T14:22:16.247-04:00">INTERIM</status_change>
            <status_change date="2011-11-14T04:00:53.639-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6007 - extended definitions of OS are without SP checks" date="2014-07-28T17:41:00.906-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:42:54.622-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:06.621-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 SP1 and Win 2K">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1619" test_ref="oval:org.mitre.oval:tst:9576"/>
        </criteria>
        <criteria operator="AND" comment="IE 5.01 SP4 and Win 2K">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="Mshtml.dll version is less than 5.0.3872.1000" test_ref="oval:org.mitre.oval:tst:9586"/>
        </criteria>
        <criteria operator="AND" comment="Win XP X86 and IE6">
          <extend_definition comment="Microsoft Windows XP is installed" definition_ref="oval:org.mitre.oval:def:105"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3492" test_ref="oval:org.mitre.oval:tst:8711"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
        </criteria>
        <criteria operator="AND" comment="Win XP X86 and IE6">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5726" test_ref="oval:org.mitre.oval:tst:9296"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
        </criteria>
        <criteria operator="AND" comment="Win 2K3 or Win XP X64 and IE6">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.3261" test_ref="oval:org.mitre.oval:tst:9630"/>
          <criteria operator="OR" comment="Win 2K3 or Win XP X64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 2K3 or Win XP X64 and IE6">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4426" test_ref="oval:org.mitre.oval:tst:9547"/>
          <criteria operator="OR" comment="Win 2K3 or Win XP X64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE7 and Win 2K3 or Win XP or Vista">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="Win XP / Win 2K3 / Win Vista">
            <extend_definition comment="Microsoft Windows XP is installed" definition_ref="oval:org.mitre.oval:def:105"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Vista is installed" definition_ref="oval:org.mitre.oval:def:228"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR and GDR">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16788" test_ref="oval:org.mitre.oval:tst:9275"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.20973" test_ref="oval:org.mitre.oval:tst:8937"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 2K8 or Vista and IE7">
          <criteria operator="OR" comment="Win 2k8 / Vista">
            <extend_definition comment="Microsoft Windows Server 2008 is installed" definition_ref="oval:org.mitre.oval:def:12824"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="Check for LDR or GDR">
            <criterion comment="Mshtml.dll version is less than 7.0.6001.18183" test_ref="oval:org.mitre.oval:tst:9164"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Mshtml.dll version is greater than or equal to 7.0.6001.22000" test_ref="oval:org.mitre.oval:tst:42152"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6001.22328" test_ref="oval:org.mitre.oval:tst:9465"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 7 and Vista or Win 2K8">
          <criteria operator="OR" comment="Vista / Win 2K8">
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.20611" test_ref="oval:org.mitre.oval:tst:44471"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12824" version="3" class="inventory">
      <metadata>
        <title>Microsoft Windows Server 2008 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_server_2008:-"/>
        <description>The operating system installed on the system is Microsoft Windows Server 2008</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-20T15:00:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </submitted>
            <status_change date="2011-09-20T15:58:40.830-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:29.117-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:52.368-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criterion comment="Windows Server 2008 is installed" test_ref="oval:org.mitre.oval:tst:7697"/>
        <criterion negate="true" comment="Windows Server 2008 R2 is installed" test_ref="oval:org.mitre.oval:tst:10317"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6000" version="3" class="vulnerability">
      <metadata>
        <title>Uninitialized Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0075" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0075"/>
        <description>Microsoft Internet Explorer 7 does not properly handle errors during attempted access to deleted objects, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to CFunctionPointer and the appending of document objects, aka "Uninitialized Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-02-10T16:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-02-13T17:01:59.993-05:00">DRAFT</status_change>
            <status_change date="2009-03-02T04:00:15.733-05:00">INTERIM</status_change>
            <status_change date="2009-03-23T04:00:14.453-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6000 - extended definitions of OS are without SP checks" date="2014-07-28T17:41:00.906-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:42:49.292-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:06.207-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE7/XP">
          <extend_definition comment="Microsoft Windows XP is installed" definition_ref="oval:org.mitre.oval:def:105"/>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16809" test_ref="oval:org.mitre.oval:tst:9568"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Server 2003 (32-bit)">
          <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16809" test_ref="oval:org.mitre.oval:tst:9568"/>
        </criteria>
        <criteria operator="AND" comment="Mshtml.dll/Vista (32-bit)">
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16809" test_ref="oval:org.mitre.oval:tst:9574"/>
        </criteria>
        <criteria operator="AND" comment="Mshtml.dll/Vista (32-bit)">
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.20996" test_ref="oval:org.mitre.oval:tst:9573"/>
        </criteria>
        <criteria operator="AND" comment="Mshtml.dll/Vista (32-bit)">
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.16000" test_ref="oval:org.mitre.oval:tst:9444"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.18203" test_ref="oval:org.mitre.oval:tst:9638"/>
        </criteria>
        <criteria operator="AND" comment="Mshtml.dll/Vista (32-bit)">
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.22355" test_ref="oval:org.mitre.oval:tst:9338"/>
        </criteria>
        <criteria operator="AND" comment="Mshtml.dll/Server 2008 (32-bit)">
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.16000" test_ref="oval:org.mitre.oval:tst:9444"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.18203" test_ref="oval:org.mitre.oval:tst:9638"/>
        </criteria>
        <criteria operator="AND" comment="Mshtml.dll/Server 2008 (32-bit)">
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.22355" test_ref="oval:org.mitre.oval:tst:9338"/>
        </criteria>
        <criteria operator="AND" comment="IE7/XP x86/x64">
          <criteria operator="OR" comment="XP x64/Server 2003 x64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16809" test_ref="oval:org.mitre.oval:tst:9568"/>
        </criteria>
        <criteria operator="AND" comment="IE7/XP x64/Server 2003 x64">
          <criteria operator="OR" comment="XP x64/Server 2003 x64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.20996" test_ref="oval:org.mitre.oval:tst:9573"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x64">
          <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16809" test_ref="oval:org.mitre.oval:tst:9568"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x64">
          <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.20996" test_ref="oval:org.mitre.oval:tst:9573"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x64/Server 2008 x64">
          <criteria operator="OR" comment="Vista x64/Server 2008 x64">
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.16000" test_ref="oval:org.mitre.oval:tst:9444"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.18203" test_ref="oval:org.mitre.oval:tst:9638"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Vista x64/Server 2008 x64">
          <criteria operator="OR" comment="Vista x64/Server 2008 x64">
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.22355" test_ref="oval:org.mitre.oval:tst:9338"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:600" version="3" class="vulnerability">
      <metadata>
        <title>Mailslot Heap Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference ref_id="CVE-2006-1314" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1314" source="CVE"/>
        <description>Heap-based buffer overflow in the Server Service (SRV.SYS driver) in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 up to SP1, and other products, allows remote attackers to execute arbitrary code via crafted first-class Mailslot messages that triggers memory corruption and bypasses size restrictions on second-class Mailslot messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-27T12:29:32.388-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:45.512-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:600 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:06:40.758-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:37.674-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win2K,SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of srv.sys is less than 5.0.2195.7087" test_ref="oval:org.mitre.oval:tst:64"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP1 (32-bit)">
          <extend_definition comment="Microsoft Windows XP SP1 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          <criterion comment="the version of srv.sys is less than 5.1.2600.1832" test_ref="oval:org.mitre.oval:tst:23"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of srv.sys is less than 5.1.2600.2893" test_ref="oval:org.mitre.oval:tst:127"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP1 (64-bit)">
          <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="the version of srv.sys is less than 5.2.3790.2691" test_ref="oval:org.mitre.oval:tst:161"/>
        </criteria>
        <criteria operator="AND" comment="S03-Gold">
          <extend_definition comment="Microsoft Windows Server 2003 (x86) Gold is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="the version of srv.sys is less than 5.2.3790.526" test_ref="oval:org.mitre.oval:tst:97"/>
        </criteria>
        <criteria operator="AND" comment="S03,SP1">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of srv.sys is less than 5.2.3790.2691" test_ref="oval:org.mitre.oval:tst:161"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5999" version="1" class="vulnerability">
      <metadata>
        <title>MSXML DTD Cross-Domain Scripting Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4029" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4029"/>
        <description>Cross-domain vulnerability in Microsoft XML Core Services 3.0 and 4.0, as used in Internet Explorer, allows remote attackers to obtain sensitive information from another domain via a crafted XML document, related to improper error checks for external DTDs, aka "MSXML DTD Cross-Domain Scripting Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-11-19T14:19:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-11-19T10:55:28.867-05:00">DRAFT</status_change>
            <status_change date="2008-12-08T04:01:04.913-05:00">INTERIM</status_change>
            <status_change date="2008-12-29T04:00:34.420-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criteria operator="OR">
          <criteria operator="AND">
            <extend_definition comment="Microsoft XML Core Services 3 is installed" definition_ref="oval:org.mitre.oval:def:415"/>
            <criterion comment="msxml3.dll version is less than 8.100.1048.0" test_ref="oval:org.mitre.oval:tst:9071"/>
          </criteria>
          <criteria operator="AND">
            <extend_definition comment="Microsoft XML Core Services 4 is installed" definition_ref="oval:org.mitre.oval:def:1002"/>
            <criterion comment="msxml4.dll version is less than 4.20.9870.0" test_ref="oval:org.mitre.oval:tst:9539"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5998" version="1" class="vulnerability">
      <metadata>
        <title>Messaging Queue Service Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3479" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3479"/>
        <description>Heap-based buffer overflow in the Microsoft Message Queuing (MSMQ) service (mqsvc.exe) in Microsoft Windows 2000 SP4 allows remote attackers to read memory contents and execute arbitrary code via a crafted RPC call, related to improper processing of parameters to string APIs, aka "Message Queuing Service Remote Code Execution Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-10-14T14:00:00">
              <contributor organization="Secure Elements, Inc.">Jeff Ito</contributor>
            </submitted>
            <status_change date="2008-10-16T14:01:55.362-04:00">DRAFT</status_change>
            <status_change date="2008-11-03T04:00:23.506-05:00">INTERIM</status_change>
            <status_change date="2008-11-24T04:00:19.191-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="mqrt.dll version is less than 5.0.0.807" test_ref="oval:org.mitre.oval:tst:9207"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5984" version="3" class="vulnerability">
      <metadata>
        <title>GDI Integer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2249" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2249"/>
        <description>Integer overflow in GDI in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to execute arbitrary code via a malformed header in a crafted WMF file, which triggers a buffer overflow, aka "GDI Integer Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-12-09T13:31:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-12-12T16:42:36.881-05:00">DRAFT</status_change>
            <status_change date="2008-12-29T04:00:33.564-05:00">INTERIM</status_change>
            <status_change date="2009-01-19T04:00:15.759-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5984 - Inclusion of Win 2003/2008 (IA-64), Vista 64-bit &amp; added LDR support too" date="2011-11-03T15:24:00.015-04:00">
              <contributor organization="SecPod Technologies">Prashanth A.</contributor>
            </modified>
            <status_change date="2011-11-03T15:28:34.418-04:00">INTERIM</status_change>
            <status_change date="2011-11-21T04:13:13.540-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for vulnerable Windows SP4 and gdi32.dll version">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="gdi32.dll version is less than 5.0.2195.7205" test_ref="oval:org.mitre.oval:tst:9222"/>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable Windows XP SP2(x86) and gdi32.dll version">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="gdi32.dll version is less than 5.1.2600.3466" test_ref="oval:org.mitre.oval:tst:8575"/>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable Windows XP SP3(x86) and gdi32.dll version">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="gdi32.dll version is less than 5.1.2600.5698" test_ref="oval:org.mitre.oval:tst:8610"/>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable Windows 2003 SP1(x86)/(x64)/(ia-64)/XP SP1(x64) and gdi32.dll version">
          <criteria operator="OR" comment="Check for vulnerable Windows 2003 SP1(x86)/(x64)/(ia-64)/XP SP1(x64)">
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:4386"/>
            <extend_definition comment="Microsoft Windows XP Professional x64 Edition SP1 is installed" definition_ref="oval:org.mitre.oval:def:720"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
          </criteria>
          <criterion comment="gdi32.dll version is less than 5.2.3790.3233" test_ref="oval:org.mitre.oval:tst:9298"/>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable Windows 2003 SP2(x86)/(x64)/(ia-64)/XP SP2(x64) and gdi32.dll version">
          <criteria operator="OR" comment="Check for vulnerable Windows 2003 SP2(x86)/(x64)/(ia-64)/XP SP2(x64)">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="gdi32.dll version is less than 5.2.3790.4396" test_ref="oval:org.mitre.oval:tst:9467"/>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable Windows Vista and gdi32.dll version">
          <criteria operator="OR" comment="Check for vulnerable Windows Vista">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criterion comment="Check if version of Gdi32.dll is less than 6.0.6000.16766" test_ref="oval:org.mitre.oval:tst:75175"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if version of Gdi32.dll is greater than or equal to 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:75193"/>
              <criterion comment="Check if version of Gdi32.dll is less than 6.0.6000.20940" test_ref="oval:org.mitre.oval:tst:74784"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for Vulnerable Windows Vista(x86)/(x64)/Server 2008(x86)/(x64)/(ia-64) and gdi32.dll version">
          <criteria operator="OR" comment="Check for Vulnerable Windows Vista(x86)/(x64)/Server 2008(x86)/(x64)/(ia-64)">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criterion comment="gdi32.dll version is less than 6.0.6001.18159" test_ref="oval:org.mitre.oval:tst:9510"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if version of Gdi32.dll is greater than or equal to 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:74690"/>
              <criterion comment="Check if version of Gdi32.dll is less than 6.0.6001.22291" test_ref="oval:org.mitre.oval:tst:75205"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5969" version="2" class="vulnerability">
      <metadata>
        <title>Vulnerability in Content-Disposition Header Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Office XP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4020" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4020"/>
        <description>Cross-site scripting (XSS) vulnerability in Microsoft Office XP SP3 allows remote attackers to inject arbitrary web script or HTML via a document that contains a "Content-Disposition: attachment" header and is accessed through a cdo: URL, which renders the content instead of raising a File Download dialog box, aka "Vulnerability in Content-Disposition Header Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-10-14T13:33:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-10-16T14:01:57.619-04:00">DRAFT</status_change>
            <status_change date="2008-11-03T04:00:23.190-05:00">INTERIM</status_change>
            <status_change date="2008-12-01T04:00:16.749-05:00">ACCEPTED</status_change>
            <modified comment="Changed product &quot;Office 2002&quot; to &quot;Office XP&quot;" date="2010-01-14T15:51:00.779-05:00">
              <contributor organization="The MITRE Corporation">Mike Lah</contributor>
            </modified>
            <status_change date="2010-01-14T15:51:20.784-05:00">INTERIM</status_change>
            <status_change date="2010-02-01T04:00:16.394-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Office XP is installed" definition_ref="oval:org.mitre.oval:def:663"/>
        <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\cdo exists" test_ref="oval:org.mitre.oval:tst:8796"/>
        <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CDO exists" test_ref="oval:org.mitre.oval:tst:9141"/>
        <criterion comment="HKEY_CLASSES_ROOT\PROTOCOLS\Handler\cdo exists" test_ref="oval:org.mitre.oval:tst:9354"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5965" version="1" class="vulnerability">
      <metadata>
        <title>TCP/IP Orphaned Connections Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1926" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1926"/>
        <description>Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allow remote attackers to cause a denial of service (TCP outage) via a series of TCP sessions that have pending data and a (1) small or (2) zero receive window size, and remain in the FIN-WAIT-1 or FIN-WAIT-2 state indefinitely, aka "TCP/IP Orphaned Connections Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-08T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-09-12T20:28:17.969-04:00">DRAFT</status_change>
            <status_change date="2009-09-28T04:00:13.525-04:00">INTERIM</status_change>
            <status_change date="2009-10-19T04:00:07.022-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
        </criteria>
        <criteria operator="OR" comment="Windows XP SP2/SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
        </criteria>
        <criteria operator="AND" comment="Windows Server 2003 X86/X64/IA64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criteria operator="OR">
            <criterion comment="the version of Tcpip.sys is less than 5.2.3790.4573" test_ref="oval:org.mitre.oval:tst:10768"/>
            <criterion comment="The version of Tcpip6.sys is less than 5.2.3790.4573" test_ref="oval:org.mitre.oval:tst:10446"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="The version of Tcpip.sys is less than 6.0.6000.16908" test_ref="oval:org.mitre.oval:tst:9931"/>
          <criterion comment="the version of Tcpip.sys is greater than or equal 6.0.6000.16000" test_ref="oval:org.mitre.oval:tst:10605"/>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64 SP1, Windows Server 2008 x86/x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="The version of Tcpip.sys is less than 6.0.6001.18311" test_ref="oval:org.mitre.oval:tst:10280"/>
          <criterion comment="the version of Tcpip.sys is greater than or equal 6.0.6001.18000" test_ref="oval:org.mitre.oval:tst:10548"/>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64 SP2, Windows Server 2008 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="The version of Tcpip.sys is less than 6.0.6002.18091" test_ref="oval:org.mitre.oval:tst:10600"/>
          <criterion comment="the version of Tcpip.sys is greater than or equal 6.0.6002.18000" test_ref="oval:org.mitre.oval:tst:10640"/>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="The version of Tcpip.sys is less than 6.0.6000.21108" test_ref="oval:org.mitre.oval:tst:10773"/>
          <criterion comment="the version of Tcpip.sys is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:10454"/>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64 SP1, Windows Server 2008 x86/x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="The version of Tcpip.sys is less than 6.0.6001.22497" test_ref="oval:org.mitre.oval:tst:10806"/>
          <criterion comment="the version of Tcpip.sys is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:10695"/>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64 SP2, Windows Server 2008 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="The version of Tcpip.sys is less than 6.0.6002.22200" test_ref="oval:org.mitre.oval:tst:9812"/>
          <criterion comment="the version of Tcpip.sys is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10619"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5963" version="3" class="vulnerability">
      <metadata>
        <title>DirectX Pointer Validation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>DirectX</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1538" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1538"/>
        <description>The QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2 performs updates to pointers without properly validating unspecified data values, which allows remote attackers to execute arbitrary code via a crafted QuickTime media file, aka "DirectX Pointer Validation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-07-14T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-07-20T15:51:19.822-04:00">DRAFT</status_change>
            <status_change date="2009-08-10T04:00:05.565-04:00">INTERIM</status_change>
            <status_change date="2009-08-31T04:00:06.977-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:3502 - obj/ste updates to conform to authoring style guide" date="2013-03-26T09:53:00.500-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-03-26T09:55:57.604-04:00">INTERIM</status_change>
            <status_change date="2013-04-15T04:00:27.744-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="DirectX 7 on Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="DirectX 7.0x Installed" test_ref="oval:org.mitre.oval:tst:1296"/>
          <criterion comment="the version of Quartz.dll is less than 6.1.9.736" test_ref="oval:org.mitre.oval:tst:10181"/>
        </criteria>
        <criteria operator="AND" comment="DirectX 8.1 on Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="DirectX 8.1 Installed" test_ref="oval:org.mitre.oval:tst:6805"/>
          <criterion comment="the version of Quartz.dll is less than 6.3.1.893" test_ref="oval:org.mitre.oval:tst:10229"/>
        </criteria>
        <criteria operator="AND" comment="DirectX 9.0 on Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="DirectX 9.0x Installed" test_ref="oval:org.mitre.oval:tst:601"/>
          <criterion comment="the version of Quartz.dll is less than 6.5.1.911" test_ref="oval:org.mitre.oval:tst:10131"/>
        </criteria>
        <criteria operator="AND" comment="DirectX 9.0 on Win XP SP2 x86">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="DirectX 9.0x Installed" test_ref="oval:org.mitre.oval:tst:601"/>
          <criterion comment="the version of Quartz.dll is less than 6.5.2600.3580" test_ref="oval:org.mitre.oval:tst:10177"/>
        </criteria>
        <criteria operator="AND" comment="DirectX 9.0 on Win XP SP3 x86">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="DirectX 9.0x Installed" test_ref="oval:org.mitre.oval:tst:601"/>
          <criterion comment="the version of Quartz.dll is less than 6.5.2600.5822" test_ref="oval:org.mitre.oval:tst:10081"/>
        </criteria>
        <criteria operator="AND" comment="DirectX 9.0 on Windows XP SP2, Server 2003 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="DirectX 9.0x Installed" test_ref="oval:org.mitre.oval:tst:601"/>
          <criterion comment="the version of Quartz.dll is less than 6.5.3790.4523" test_ref="oval:org.mitre.oval:tst:10047"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5942" version="9" class="vulnerability">
      <metadata>
        <title>SPN Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Windows Media Player 6.4</product>
          <product>Windows Media Server 4.1</product>
          <product>Windows Media Server 9</product>
          <product>Windows Media Format Runtime 7.1</product>
          <product>Windows Media Format Runtime 9.5</product>
          <product>Windows Media Format Runtime 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3009" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3009"/>
        <description>Microsoft Windows Media Player 6.4, Windows Media Format Runtime 7.1 through 11, and Windows Media Services 4.1, 9, and 2008 do not properly use the Service Principal Name (SPN) identifier when validating replies to authentication requests, which allows remote servers to execute arbitrary code via vectors that employ NTLM credential reflection, aka "SPN Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-12-10T10:44:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-12-12T16:42:41.693-05:00">DRAFT</status_change>
            <status_change date="2008-12-29T04:00:32.351-05:00">INTERIM</status_change>
            <status_change date="2009-01-19T04:00:14.339-05:00">ACCEPTED</status_change>
            <modified comment="Added Windows Server 2008 SP2 as affected version" date="2009-05-07T10:34:00.056-04:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2009-05-07T10:36:28.062-04:00">INTERIM</status_change>
            <status_change date="2009-05-25T04:01:50.396-04:00">ACCEPTED</status_change>
            <modified comment="Including checks for Windows Media Player 6.4" date="2009-12-01T17:32:00.359-05:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2009-12-01T17:33:37.367-05:00">INTERIM</status_change>
            <status_change date="2009-12-21T04:00:43.809-05:00">ACCEPTED</status_change>
            <modified comment="corrected file name from Nscm.exe to Nsum.exe for obj:6532" date="2010-04-16T14:46:00.908-04:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2010-04-16T14:50:18.481-04:00">INTERIM</status_change>
            <status_change date="2010-05-17T04:00:08.946-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5942 - def:5942 &amp; def:5689, Enhanced to cover WinVista, 2008, 2003 &amp; also 64-bit with service packs" date="2011-11-15T14:56:00.873-05:00">
              <contributor organization="SecPod Technologies">Pradeep R B</contributor>
            </modified>
            <status_change date="2011-11-15T14:58:45.961-05:00">INTERIM</status_change>
            <status_change date="2011-12-05T04:00:34.404-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5942 - extended definitions of OS are without SP checks" date="2014-07-28T17:41:00.906-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:42:51.130-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:05.949-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for Media player 6.4">
          <extend_definition comment="Windows Media Player 6.4 is installed." definition_ref="oval:org.mitre.oval:def:6408"/>
          <criteria operator="OR" comment="Check for Windows 2000/XP/2003">
            <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
          </criteria>
          <criterion comment="the version of Strmdll.dll is less than 4.1.0.3937" test_ref="oval:org.mitre.oval:tst:11104"/>
          <criteria operator="OR" comment="Check for Windows XP/2003">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <criterion comment="the version of Wstrmdll.dll is less than 4.1.0.3937" test_ref="oval:org.mitre.oval:tst:11180"/>
        </criteria>
        <criteria operator="AND" comment="Check for Windows 2000,Media Services 4.1 and Nsum.exe version">
          <extend_definition comment="Microsoft Media Services 4.1 is installed" definition_ref="oval:org.mitre.oval:def:5705"/>
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <criterion comment="Nsum.exe version is less than 4.1.0.3936" test_ref="oval:org.mitre.oval:tst:9602"/>
        </criteria>
        <criteria operator="AND" comment="Check for Media Services 9">
          <extend_definition comment="Microsoft Media Services 9 is installed" definition_ref="oval:org.mitre.oval:def:5844"/>
          <criteria operator="OR" comment="Check for vulnerable Media Services 9 and Wmsserver.dll version">
            <criteria operator="AND" comment="Check for Windows 2003">
              <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
              <criterion comment="Wmsserver.dll version is less than 9.1.1.3845" test_ref="oval:org.mitre.oval:tst:9156"/>
            </criteria>
            <criteria operator="AND" comment="Check for Windows 2003">
              <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
              <criterion comment="Wmsserver.dll version is less than 9.1.1.5000" test_ref="oval:org.mitre.oval:tst:9492"/>
            </criteria>
            <criteria operator="AND" comment="Check for Windows 2008-32/64 and Wmsserver.dll version">
              <criteria operator="OR" comment="Check for Windows 2008-32/64">
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criterion comment="Wmsserver.dll version is less than 9.5.6001.18161" test_ref="oval:org.mitre.oval:tst:9250"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for Media Player 7.1,Windows 2000 and Wmstream.dll version">
          <extend_definition comment="Windows Media Player v7.1 is installed." definition_ref="oval:org.mitre.oval:def:1386"/>
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <criterion comment="Wmstream.dll version is less than 7.10.0.3082" test_ref="oval:org.mitre.oval:tst:8658"/>
        </criteria>
        <criteria operator="AND" comment="Check for Media Player 9">
          <extend_definition comment="Windows Media Player v9 is installed." definition_ref="oval:org.mitre.oval:def:2147"/>
          <criteria operator="OR" comment="Check for vulnerable Media Player 9">
            <criteria operator="AND" comment="Check for Windows 2000/XP and Wmnetmgr.dll version">
              <criterion comment="Wmnetmgr.dll version is less than 9.0.0.3268" test_ref="oval:org.mitre.oval:tst:9440"/>
              <criteria operator="OR" comment="Check for Windows 2000/XP">
                <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
                <extend_definition comment="Microsoft Windows XP is installed" definition_ref="oval:org.mitre.oval:def:105"/>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Check for Windows XP and Wmnetmgr.dll version">
              <criterion comment="Wmnetmgr.dll version is less than 9.0.0.4504" test_ref="oval:org.mitre.oval:tst:9564"/>
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for Media Player v10">
          <extend_definition comment="Windows Media Player v10 is installed." definition_ref="oval:org.mitre.oval:def:2172"/>
          <criteria operator="OR" comment="Check for vulnerable Media Player 10">
            <criteria operator="AND" comment="Check for Windows XP and Wmnetmgr.dll version">
              <criterion comment="Wmnetmgr.dll version is less than 10.0.0.3703" test_ref="oval:org.mitre.oval:tst:9104"/>
              <criteria operator="OR" comment="Check for Windows XP">
                <extend_definition comment="Microsoft Windows XP is installed" definition_ref="oval:org.mitre.oval:def:105"/>
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Check for Windows 2003 and Wmnetmgr.dll version">
              <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
              <criterion comment="Wmnetmgr.dll version is less than 10.0.0.3711" test_ref="oval:org.mitre.oval:tst:9257"/>
            </criteria>
            <criteria operator="AND" comment="Check for Windows 2003 and Wmnetmgr.dll version">
              <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
              <criterion comment="Wmnetmgr.dll version is less than 10.0.0.4001" test_ref="oval:org.mitre.oval:tst:9445"/>
            </criteria>
            <criteria operator="AND" comment="Check for Windows XP/2003 and Wmnetmgr.dll version">
              <criteria operator="OR" comment="Check for Windows XP/2003">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Wmnetmgr.dll version is less than 10.0.0.3711" test_ref="oval:org.mitre.oval:tst:9257"/>
            </criteria>
            <criteria operator="AND" comment="Check for Windows XP/2003(x64) and Wmnetmgr.dll version">
              <criteria operator="OR" comment="Check for Windows XP/2003(x64)">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Wmnetmgr.dll version is less than 10.0.0.4001" test_ref="oval:org.mitre.oval:tst:9445"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for Media Player v11">
          <extend_definition comment="Windows Media Player v11 is installed." definition_ref="oval:org.mitre.oval:def:2126"/>
          <criteria operator="OR" comment="Check for vulnerable Media Player 10">
            <criteria operator="AND" comment="Check for Windows XP(32)/(64) and Wmnetmgr.dll version">
              <criterion comment="Wmnetmgr.dll version is less than 11.0.5721.5251" test_ref="oval:org.mitre.oval:tst:9534"/>
              <criteria operator="OR" comment="Check for Windows XP(32)/(64)">
                <extend_definition comment="Microsoft Windows XP is installed" definition_ref="oval:org.mitre.oval:def:105"/>
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Check for Windows Vista and Wmnetmgr.dll version">
              <criterion comment="Check if version of Wmnetmgr.dll is less than 11.0.6000.6346" test_ref="oval:org.mitre.oval:tst:77438"/>
              <criteria operator="OR" comment="Check for Windows Vista">
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Check for Windows Vista/2008 and Wmnetmgr.dll version">
              <criterion comment="Check if version of Wmnetmgr.dll is less than 11.0.6001.7001" test_ref="oval:org.mitre.oval:tst:77313"/>
              <criteria operator="OR" comment="Check for Windows Vista/2008">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:594" version="5" class="vulnerability" deprecated="true">
      <metadata>
        <title>Windows Messenger 6 libpng Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>MSN Messenger</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0597" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0597"/>
        <description>Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_handle_tRNS function does not properly validate the length of transparency chunk (tRNS) data, or the (2) png_handle_sBIT or (3) png_handle_hIST functions do not perform sufficient bounds checking.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-29T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-03-29T08:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-13T12:15:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-05-04T12:33:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-11-24T12:00:00.000-04:00" comment="Added wrt-620 to see if MSN Messenger 6.2 is installed.  Changed wrt-195 to check for 6.2.0205 or later.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <modified date="2005-12-20T07:05:00.000-04:00" comment="Added wrt-195.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-04T08:04:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:2359" date="2007-03-06T08:06:00.649-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-06T08:07:06.751-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:21.723-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:1436" date="2007-04-23T12:05:00.002-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:31:50.117-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:1435" date="2007-04-23T12:05:00.788-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:11:07.574-04:00">ACCEPTED</status_change>
            <status_change date="2010-03-01T11:12:00.000-05:00">DEPRECATED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:1436 - vulnerabilities for VMware and inventories for VMware Workstation, VMware View and VMware Player." date="2013-06-21T12:00:00.019-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="MSN Messenger 6.2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2520"/>
        <criterion comment="MSN Messenger 6.2.0205 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2519"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5930" version="1" class="vulnerability">
      <metadata>
        <title>AVI Integer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1546" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1546"/>
        <description>Integer overflow in Avifil32.dll in the Windows Media file handling functionality in Microsoft Windows allows remote attackers to execute arbitrary code on a Windows 2000 SP4 system via a crafted AVI file, or cause a denial of service on a Windows XP SP2 or SP3, Server 2003 SP2, Vista Gold, SP1, or SP2, or Server 2008 Gold or SP2 system via a crafted AVI file, aka "AVI Integer Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-07-28T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-08-19T14:58:08.166-04:00">DRAFT</status_change>
            <status_change date="2009-09-07T04:00:09.561-04:00">INTERIM</status_change>
            <status_change date="2009-09-28T04:00:12.570-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Avifil32.dll is less than 5.0.2195.7316" test_ref="oval:org.mitre.oval:tst:10408"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="the version of Avifil32.dll is less than 5.1.2600.3585" test_ref="oval:org.mitre.oval:tst:10705"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of Avifil32.dll is less than 5.1.2600.5827" test_ref="oval:org.mitre.oval:tst:10660"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of Avifil32.dll is less than 5.2.3790.4527" test_ref="oval:org.mitre.oval:tst:10576"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="the version of Avifil32.dll is less than 6.0.6000.16868" test_ref="oval:org.mitre.oval:tst:10489"/>
          <criterion comment="the version of Avifil32.dll is greater than or equal 6.0.6000.16000" test_ref="oval:org.mitre.oval:tst:10678"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="the version of Avifil32.dll is less than 6.0.6000.21065" test_ref="oval:org.mitre.oval:tst:10465"/>
          <criterion comment="the version of Avifil32.dll is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:10566"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of Avifil32.dll is less than 6.0.6001.18270" test_ref="oval:org.mitre.oval:tst:10712"/>
          <criterion comment="the version of Avifil32.dll is greater than or equal 6.0.6001.18000" test_ref="oval:org.mitre.oval:tst:10375"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of Avifil32.dll is less than 6.0.6001.22447" test_ref="oval:org.mitre.oval:tst:10665"/>
          <criterion comment="the version of Avifil32.dll is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:10163"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="the version of Avifil32.dll is less than 6.0.6002.18049" test_ref="oval:org.mitre.oval:tst:10707"/>
          <criterion comment="the version of Avifil32.dll is greater than or equal 6.0.6002.18000" test_ref="oval:org.mitre.oval:tst:10051"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="the version of Avifil32.dll is less than 6.0.6002.22150" test_ref="oval:org.mitre.oval:tst:10627"/>
          <criterion comment="the version of Avifil32.dll is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10506"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5926" version="7" class="vulnerability">
      <metadata>
        <title>Windows 2000 NNTP Component Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Network News Transport Protocol (NNTP)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0574" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0574"/>
        <description>The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003, Exchange 2000 Server, and Exchange Server 2003 allows remote attackers to execute arbitrary code via XPAT patterns, possibly related to improper length validation and an "unchecked buffer," leading to off-by-one and heap-based buffer overflows.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-14T08:58:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-10-20T02:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-31T04:13:00.000-04:00" comment="Replaced reference to obj:1374 with reference to obj:1550 since it references Product\Options and not ProductOptions in the controlset registry key.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:53:59.853-05:00">ACCEPTED</status_change>
            <modified comment="Multiple corrections and update to POSIX compatibility for ste:2884" date="2010-11-29T16:14:00.692-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-11-29T16:14:39.987-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:01:03.271-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:44:39.642-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:03:14.450-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows 2000 Server is installed">
            <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
            <criteria operator="OR" comment="Windows NT server product option">
              <criterion comment="this is an NT Server (stand-alone)" negate="false" test_ref="oval:org.mitre.oval:tst:2408"/>
              <criterion comment="this is an NT Server (domain controller)" negate="false" test_ref="oval:org.mitre.oval:tst:3035"/>
            </criteria>
          </criteria>
          <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3079"/>
          <criterion comment="the version of nntpsvc.dll is less than 5.0.2195.6972" negate="false" test_ref="oval:org.mitre.oval:tst:274"/>
          <criterion comment="Patch Windows2000-KB883935-x86-ENU.exe Installed" negate="true" test_ref="oval:org.mitre.oval:tst:273"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the NNTP service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2757"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5923" version="4" class="vulnerability">
      <metadata>
        <title>Microsoft Color Management System Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2245" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2245"/>
        <description>Heap-based buffer overflow in the InternalOpenColorProfile function in mscms.dll in Microsoft Windows Image Color Management System (MSCMS) in the Image Color Management (ICM) component on Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted image file.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-13T09:28:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-08-14T15:02:38.460-04:00">DRAFT</status_change>
            <modified comment="Replaced CVE-2008-2463 with CVE-2008-2245" date="2008-08-26T10:39:00.148-04:00">
              <contributor organization="Secure Elements, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2008-09-15T04:00:26.271-04:00">INTERIM</status_change>
            <status_change date="2008-10-06T04:00:13.842-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5923 - October Patch Tuesday" date="2011-10-14T15:55:00.086-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-10-14T15:57:08.092-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:04:12.262-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of mscms.dll is less than 5.0.2195.7162" test_ref="oval:org.mitre.oval:tst:8571"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows XP SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of mscms.dll is less than 5.1.2600.3396" test_ref="oval:org.mitre.oval:tst:8739"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows XP (x86) SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of mscms.dll is less than 5.1.2600.5627" test_ref="oval:org.mitre.oval:tst:8660"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows XP x64 SP1/Server 2003 SP1 (x86)/(x64)/(ia-64)">
          <criteria operator="OR" comment="Windows XP x64 SP1/Server 2003 SP1 (x86)/(x64)/(ia-64)">
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows XP Professional x64 Edition SP1 is installed" definition_ref="oval:org.mitre.oval:def:720"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:4386"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
          </criteria>
          <criterion comment="the version of mscms.dll is less than 5.2.3790.3163" test_ref="oval:org.mitre.oval:tst:8995"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows XP x64 SP2/Server 2003 SP2 (x86)/(x64)/(ia-64)">
          <criteria operator="OR" comment="Windows XP x64 SP2/Server 2003 SP2 (x86)/(x64)/(ia-64)">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of mscms.dll is less than 5.2.3790.4320" test_ref="oval:org.mitre.oval:tst:9047"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5913" version="5" class="vulnerability">
      <metadata>
        <title>HTML Component Handling Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2259" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2259"/>
        <description>Microsoft Internet Explorer 6 and 7 does not perform proper "argument validation" during print preview, which allows remote attackers to execute arbitrary code via unknown vectors, aka "HTML Component Handling Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-13T09:28:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-08-14T15:02:39.306-04:00">DRAFT</status_change>
            <status_change date="2008-09-01T04:01:16.985-04:00">INTERIM</status_change>
            <status_change date="2008-09-22T04:00:37.515-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:9018 - Included LDR support &amp; added new state to match correct version." date="2011-10-25T14:07:00.717-04:00">
              <contributor organization="SecPod Technologies">Pooja Shetty</contributor>
            </modified>
            <status_change date="2011-10-25T14:12:06.619-04:00">INTERIM</status_change>
            <status_change date="2011-11-14T04:00:51.883-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5913 - extended definitions of OS are without SP checks" date="2014-07-28T17:41:00.906-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:42:52.081-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:05.726-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win 2K + IE6 vulnerable version">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1613" test_ref="oval:org.mitre.oval:tst:8781"/>
        </criteria>
        <criteria operator="AND" comment="Win XP + IE 6">
          <extend_definition comment="Microsoft Windows XP is installed" definition_ref="oval:org.mitre.oval:def:105"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3395" test_ref="oval:org.mitre.oval:tst:8921"/>
        </criteria>
        <criteria operator="AND" comment="Win XP + IE 6">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5626" test_ref="oval:org.mitre.oval:tst:9128"/>
        </criteria>
        <criteria operator="AND" comment="Win XP /  Win 2K3 + IE 7">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="Win XP / Win 2K3">
            <extend_definition comment="Microsoft Windows XP is installed" definition_ref="oval:org.mitre.oval:def:105"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR / GDR">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16705" test_ref="oval:org.mitre.oval:tst:9018"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Check if the version mshtml.dll is less than 7.0.6000.20861" test_ref="oval:org.mitre.oval:tst:44137"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 2K3 / Win XP X64 and IE 6">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.3167" test_ref="oval:org.mitre.oval:tst:8958"/>
          <criteria operator="OR" comment="Win 2K3 / Win XP X64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win XP X64 / Win 2K3">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4324" test_ref="oval:org.mitre.oval:tst:8988"/>
          <criteria operator="OR" comment="Win 2K3 / Win XP X64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win Vista and IE7">
          <extend_definition comment="Microsoft Windows Vista is installed" definition_ref="oval:org.mitre.oval:def:228"/>
          <criteria operator="OR" comment="Check for LDR and GDR">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16711" test_ref="oval:org.mitre.oval:tst:8163"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.20868" test_ref="oval:org.mitre.oval:tst:44258"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
        </criteria>
        <criteria operator="AND" comment="Win Vista / Win 2K8 and IE7">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="Win Vista/ Win 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR /GDR">
            <criterion comment="Mshtml.dll version is less than 7.0.6001.18099" test_ref="oval:org.mitre.oval:tst:9108"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Mshtml.dll version is greater than or equal to 7.0.6001.22000" test_ref="oval:org.mitre.oval:tst:42152"/>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6001.22212" test_ref="oval:org.mitre.oval:tst:44416"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5912" version="6" class="vulnerability">
      <metadata>
        <title>Windows Driver Class Registration Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1125" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1125"/>
        <description>The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate an argument to an unspecified system call, which allows local users to gain privileges via a crafted application, aka "Windows Driver Class Registration Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-06-09T14:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-06-15T17:07:26.238-04:00">DRAFT</status_change>
            <status_change date="2009-07-06T04:00:28.381-04:00">INTERIM</status_change>
            <status_change date="2009-07-21T07:45:57.636-04:00">ACCEPTED</status_change>
            <modified comment="Changed operation attribute to 'greater than or equals'" date="2010-02-10T13:05:00.517-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2010-02-10T13:05:54.060-05:00">INTERIM</status_change>
            <modified comment="Changed operation attribute to 'greater than or equals'" date="2010-02-10T13:05:00.923-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2010-03-01T04:00:04.860-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5912 - Modified GDR/LDR service branch format to read easier, removed duplicate, and updated extended def for Vista." date="2011-01-31T14:14:00.299-05:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-01-31T14:15:03.287-05:00">INTERIM</status_change>
            <status_change date="2011-02-21T04:00:55.575-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5160 - contains tests with modified comments and all dependences" date="2014-02-13T12:19:00.287-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:23:01.729-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:11.876-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable on Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of win32k.sys is less than 5.0.2195.7279" test_ref="oval:org.mitre.oval:tst:10057"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows XP x86 SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="the version of win32k.sys is less than 5.1.2600.3556" test_ref="oval:org.mitre.oval:tst:10075"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows XP x86 SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of win32k.sys is less than 5.1.2600.5796" test_ref="oval:org.mitre.oval:tst:9735"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of win32k.sys is less than 5.2.3790.4497" test_ref="oval:org.mitre.oval:tst:9867"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Vista x86/x64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of win32k.sys is less than 6.0.6000.16849" test_ref="oval:org.mitre.oval:tst:10055"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of win32k.sys is less than 6.0.6000.21044" test_ref="oval:org.mitre.oval:tst:9650"/>
              <criterion comment="the version of win32k.sys is greater than 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9977"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Vista x86/x64 SP1, all Server 2008 x86/x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of win32k.sys is less than 6.0.6001.18246" test_ref="oval:org.mitre.oval:tst:9997"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of win32k.sys is less than 6.0.6001.22416" test_ref="oval:org.mitre.oval:tst:10213"/>
              <criterion comment="the version of win32k.sys is greater than 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:10142"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Vista x86/x64 SP2, Server 2008 x86/64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of win32k.sys is less than 6.0.6002.18023" test_ref="oval:org.mitre.oval:tst:9699"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of win32k.sys is less than 6.0.6002.22119" test_ref="oval:org.mitre.oval:tst:9663"/>
              <criterion comment="the version of win32k.sys is greater than 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10124"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5903" version="5" class="vulnerability">
      <metadata>
        <title>Uninitialized Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Internet Explorer 7</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4260" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4260"/>
        <description>Microsoft Internet Explorer 7 sometimes attempts to access a deleted object, which allows remote attackers to execute arbitrary code via a crafted HTML document that triggers memory corruption, aka "Uninitialized Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-12-09T13:31:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-12-12T16:42:43.552-05:00">DRAFT</status_change>
            <status_change date="2008-12-29T04:00:31.360-05:00">INTERIM</status_change>
            <status_change date="2009-01-19T04:00:13.195-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5903 - Submission from SecPod" date="2011-11-14T13:25:00.552-05:00">
              <contributor organization="SecPod Technologies">Pradeep R B</contributor>
            </modified>
            <status_change date="2011-11-14T13:28:27.480-05:00">INTERIM</status_change>
            <status_change date="2011-12-05T04:00:33.384-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5903 - extended definitions of OS are without SP checks" date="2014-07-28T17:41:00.906-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:42:52.557-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:05.546-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
        <criteria operator="OR" comment="Vulnerable IE 7">
          <criteria operator="AND" comment="Check for Vulnerable XP(x86)/(x64)/2003 (ia-64) and Mshtml.dll version">
            <criteria operator="OR" comment="Check for Vulnerable XP(x86)/(x64)/2003 (ia-64)">
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
              <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            </criteria>
            <criteria operator="OR" comment="Check for LDR/GDR">
              <criteria operator="AND" comment="Check for LDR">
                <criterion comment="Check if version of Mshtml.dll is less than 7.0.6000.20935" test_ref="oval:org.mitre.oval:tst:77411"/>
                <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              </criteria>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.16762" test_ref="oval:org.mitre.oval:tst:9192"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Check for Vulnerable Windows Vista (x86)/(x64) and Mshtml.dll version">
            <criteria operator="OR" comment="Check for Vulnerable Windows Vista (x86)/(x64)">
              <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
              <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            </criteria>
            <criteria operator="OR" comment="Check for LDR\GDR">
              <criterion comment="Mshtml.dll version is less than 7.0.6000.16764" test_ref="oval:org.mitre.oval:tst:9403"/>
              <criteria operator="AND" comment="Check for LDR">
                <criterion comment="Mshtml.dll version is less than 7.0.6000.20937" test_ref="oval:org.mitre.oval:tst:9083"/>
                <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Check for Vulnerable Vista(x86)/(x64)/2008(x86)/(x64) and Mshtml.dll version">
            <criteria operator="OR" comment="Check for Vulnerable Vista(x86)/(x64)/2008(x86)/(x64)">
              <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
              <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
              <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            </criteria>
            <criteria operator="OR" comment="Check for LDR\GDR">
              <criterion comment="Mshtml.dll version is less than 7.0.6001.18157" test_ref="oval:org.mitre.oval:tst:9575"/>
              <criteria operator="AND" comment="Check for LDR">
                <criterion comment="Mshtml.dll version is less than 7.0.6001.22288" test_ref="oval:org.mitre.oval:tst:9182"/>
                <criterion comment="Mshtml.dll version is greater than or equal to 7.0.6001.22000" test_ref="oval:org.mitre.oval:tst:42152"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5902" version="3" class="vulnerability">
      <metadata>
        <title>Windows Kernel Window Creation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2250" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2250"/>
        <description>The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate window properties sent from a parent window to a child window during creation of a new window, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Window Creation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-10-14T13:33:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-10-16T14:02:02.391-04:00">DRAFT</status_change>
            <status_change date="2008-11-03T04:00:22.284-05:00">INTERIM</status_change>
            <status_change date="2008-11-24T04:00:17.039-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5902 - def:5902, def:6010 and def:6045 are updated with LDR inclusion" date="2011-10-28T20:15:00.324-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2011-10-28T20:33:42.808-04:00">INTERIM</status_change>
            <status_change date="2011-11-14T04:00:51.030-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="windows 2000 sp4/version">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Win32k.sys version is less than 5.0.2195.7194" test_ref="oval:org.mitre.oval:tst:9225"/>
        </criteria>
        <criteria operator="AND" comment="win xp sp2(32 bit)/version">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="Win32k.sys version is less than 5.1.2600.3446" test_ref="oval:org.mitre.oval:tst:8612"/>
        </criteria>
        <criteria operator="AND" comment="win xp sp3(32 bit)/version">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Win32k.sys version is less than 5.1.2600.5676" test_ref="oval:org.mitre.oval:tst:9293"/>
        </criteria>
        <criteria operator="AND" comment="server 2003sp1(32/64/ia-64)/win xp professional 64/version">
          <criteria operator="OR" comment="server 2003 sp1(32/64/ia-64)/win xp professional 64">
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:4386"/>
            <extend_definition comment="Microsoft Windows XP Professional x64 Edition SP1 is installed" definition_ref="oval:org.mitre.oval:def:720"/>
          </criteria>
          <criterion comment="Win32k.sys version is less than 5.2.3790.3212" test_ref="oval:org.mitre.oval:tst:9353"/>
        </criteria>
        <criteria operator="AND" comment="server 2003sp2 (32/64/ia-64)/win xp sp2 professional 64)/version">
          <criteria operator="OR" comment="server 2003sp2 (32/64/ia-64)/win xp sp2 professional 64">
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          </criteria>
          <criterion comment="Win32k.sys version is less than 5.2.3790.4375" test_ref="oval:org.mitre.oval:tst:9112"/>
        </criteria>
        <criteria operator="AND" comment="vista/server 2008(32/64)/version">
          <criteria operator="OR" comment="vista/server 2008(32/64)">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="GDR/LDR">
            <criterion comment="Win32k.sys version is less than 6.0.6000.16750" test_ref="oval:org.mitre.oval:tst:8810"/>
            <criteria operator="AND" comment="LDR range">
              <criterion comment="Check if the version of Win32k.sys is less than 6.0.6000.20917" test_ref="oval:org.mitre.oval:tst:43564"/>
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:44402"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="vista sp1(32/64)/server 2008 ia-64/version">
          <criteria operator="OR" comment="vista sp1(32/64)/server 2008 ia-64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criteria operator="OR" comment="GDR/LDR">
            <criterion comment="Win32k.sys version is less than 6.0.6001.18141" test_ref="oval:org.mitre.oval:tst:8928"/>
            <criteria operator="AND" comment="LDR range">
              <criterion comment="Check if the version of Win32k.sys is less than 6.0.6001.22265" test_ref="oval:org.mitre.oval:tst:44031"/>
              <criterion comment="the version of win32k.sys is greater than or equal to 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:43082"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5901" version="8" class="vulnerability">
      <metadata>
        <title>Window Location Property Cross-Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 5.01</product>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2947" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2947"/>
        <description>Cross-domain vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, and 7 allows remote attackers to access restricted information from other domains via JavaScript that uses the Object data type for the value of a (1) location or (2) location.href property, related to incorrect determination of the origin of web script, aka "Window Location Property Cross-Domain Vulnerability." NOTE: according to Microsoft, CVE-2008-2948 and CVE-2008-2949 are duplicates of this issue, probably different attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-10-14T13:33:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-10-16T14:02:08.277-04:00">DRAFT</status_change>
            <status_change date="2008-11-03T04:00:21.593-05:00">INTERIM</status_change>
            <status_change date="2008-11-24T04:00:16.218-05:00">ACCEPTED</status_change>
            <modified comment="Added smart criteria to support multiple versions of mshtml.sll - 16000 and 20000" date="2008-12-12T16:29:00.170-05:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2008-12-12T16:31:06.190-05:00">INTERIM</status_change>
            <status_change date="2008-12-29T04:00:30.132-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5901 - ste:4424 is updated to correct version. added 5 new definitions for ms08-058 are not in the repository" date="2011-10-28T20:15:00.656-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2011-10-28T20:28:26.230-04:00">INTERIM</status_change>
            <status_change date="2011-11-14T04:00:50.154-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4503 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:24:13.656-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:11.602-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5901 - extended definitions of OS are without SP checks" date="2014-07-28T17:39:00.892-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:41:17.095-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:05.081-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 and Win 2KSo4">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1615" test_ref="oval:org.mitre.oval:tst:8845"/>
        </criteria>
        <criteria operator="AND" comment="IE 5.01 SP4 and Win 2K">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="Mshtml.dll version is less than 5.0.3868.2000" test_ref="oval:org.mitre.oval:tst:9144"/>
        </criteria>
        <criteria operator="AND" comment="Win XP X86 and IE6">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3429" test_ref="oval:org.mitre.oval:tst:9320"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
        </criteria>
        <criteria operator="AND" comment="Win XP X86 and IE6">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5659" test_ref="oval:org.mitre.oval:tst:9099"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
        </criteria>
        <criteria operator="AND" comment="IE7 and Win XP or Win 2K3">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="Win XP or Win 2K3">
            <extend_definition comment="Microsoft Windows XP is installed" definition_ref="oval:org.mitre.oval:def:105"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR / GDR">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16735" test_ref="oval:org.mitre.oval:tst:8577"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.20900" test_ref="oval:org.mitre.oval:tst:44256"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE6 and Win 2K3 or Win XP X64">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.3194" test_ref="oval:org.mitre.oval:tst:8956"/>
          <criteria operator="OR" comment="Win XP X64 or Win 2K3">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 2K3 or Win XP X64 and IE6">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4357" test_ref="oval:org.mitre.oval:tst:8902"/>
          <criteria operator="OR" comment="Win 2K3 or Win XP X64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE7 and Vista">
          <extend_definition comment="Microsoft Windows Vista is installed" definition_ref="oval:org.mitre.oval:def:228"/>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16757" test_ref="oval:org.mitre.oval:tst:8644"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.20927" test_ref="oval:org.mitre.oval:tst:9560"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 2K8 / Vista and IE7">
          <criteria operator="OR" comment="Win 2K8 / Vista">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR / GDR">
            <criterion comment="Mshtml.dll version is less than 7.0.6001.18148" test_ref="oval:org.mitre.oval:tst:9509"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Mshtml.dll version is greater than or equal to 7.0.6001.22000" test_ref="oval:org.mitre.oval:tst:42152"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6001.22260" test_ref="oval:org.mitre.oval:tst:9350"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
        </criteria>
        <criteria operator="AND" comment="Win 2K8 ia 64">
          <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          <criteria operator="OR" comment="Check for LDR / GDR">
            <criterion comment="Check if the version of mshtml.dll is less than 7.0.6001.18137" test_ref="oval:org.mitre.oval:tst:44400"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Mshtml.dll version is less than 7.0.6001.22260" test_ref="oval:org.mitre.oval:tst:9350"/>
              <criterion comment="Mshtml.dll version is greater than or equal to 7.0.6001.22000" test_ref="oval:org.mitre.oval:tst:42152"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:59" version="6" class="vulnerability">
      <metadata>
        <title>Microsoft Windows RPC Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Remote Procedure Call (RPC)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1561" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1561"/>
        <description>The RPC component in Windows 2000, Windows NT 4.0, and Windows XP allows remote attackers to cause a denial of service (disabled RPC service) via a malformed packet to the RPC Endpoint Mapper at TCP port 135, which triggers a null pointer dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2005-03-07T12:00:00.000-04:00" comment="modified wrt-222 - changed pattern match">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-03-09T07:55:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-29T07:59:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Multiple corrections and update to POSIX compatibility for ste:2878" date="2010-11-29T16:13:00.904-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-11-29T16:14:04.901-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:01:02.953-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:19.928-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:03:14.116-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="File %windir%\system32\rpcrt4.dll version is less than 5.0.2195.6106" negate="false" test_ref="oval:org.mitre.oval:tst:3002"/>
        <criterion comment="Patch Q331953_W2K_SP4_X86_EN.exe Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3001"/>
        <criterion comment="Patch Windows2000-KB823980-x86-ENU.exe Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3000"/>
        <criterion comment="SP4 or later Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3073"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5894" version="5" class="vulnerability">
      <metadata>
        <title>DataGrid Control Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Visual Basic 6.0</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4252" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4252"/>
        <description>The DataGrid ActiveX control in Microsoft Visual Basic 6.0 and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 does not properly handle errors during access to incorrectly initialized objects, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to corruption of the "system state," aka "DataGrid Control Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-12-09T13:31:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-12-12T16:42:47.411-05:00">DRAFT</status_change>
            <status_change date="2008-12-29T04:00:29.700-05:00">INTERIM</status_change>
            <status_change date="2009-01-19T04:00:12.445-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5894 - updated by including Visual FoxPro Inventory criteria" date="2011-11-14T13:22:00.233-05:00">
              <contributor organization="SecPod Technologies">Pradeep R B</contributor>
            </modified>
            <status_change date="2011-11-14T13:23:34.184-05:00">INTERIM</status_change>
            <status_change date="2011-12-05T04:00:33.000-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5894 - New inventory definition for VB6, and updates to definitions incorrectly checking VBA inventory instead of VB6." date="2012-10-25T16:38:00.742-04:00">
              <contributor organization="SecPod Technologies">Pradeep R B</contributor>
            </modified>
            <status_change date="2012-10-25T16:58:34.478-04:00">INTERIM</status_change>
            <status_change date="2012-11-12T04:00:34.888-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Vulnerable Visual Basic 6.0 or VisualFoxPro">
          <extend_definition comment="Microsoft Visual FoxPro is installed" definition_ref="oval:org.mitre.oval:def:14198"/>
          <extend_definition comment="Microsoft Visual Basic 6.0 is installed" definition_ref="oval:org.mitre.oval:def:15369"/>
        </criteria>
        <criterion comment="Mscomct2.ocx version is less than 6.1.98.12" test_ref="oval:org.mitre.oval:tst:9209"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5890" version="9" class="vulnerability">
      <metadata>
        <title>LSASS Recursive Stack Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1928" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1928"/>
        <description>Stack consumption vulnerability in the LDAP service in Active Directory on Microsoft Windows 2000 SP4, Server 2003 SP2, and Server 2008 Gold and SP2; Active Directory Application Mode (ADAM) on Windows XP SP2 and SP3 and Server 2003 SP2; and Active Directory Lightweight Directory Service (AD LDS) on Windows Server 2008 Gold and SP2 allows remote attackers to cause a denial of service (system hang) via a malformed (1) LDAP or (2) LDAPS request, aka "LSASS Recursive Stack Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-10T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-11-12T15:32:32.104-05:00">DRAFT</status_change>
            <status_change date="2009-11-30T04:00:13.755-05:00">INTERIM</status_change>
            <status_change date="2009-12-21T04:00:42.176-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:5285 - obj:5285 is pointing to windows\system32 directory. But, adamdsa.dll file by default will be in windows\ADAM directory" date="2011-07-14T10:24:00.833-04:00">
              <contributor organization="SecPod Technologies">Sharath S</contributor>
            </modified>
            <status_change date="2011-07-14T10:26:46.362-04:00">INTERIM</status_change>
            <status_change date="2011-08-01T04:00:56.259-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5890 - def:5890 - &quot;Added Microsoft Windows Server 2003 SP2 itanium criteria.&quot;" date="2011-10-27T10:15:00.814-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-10-27T10:17:33.916-04:00">INTERIM</status_change>
            <status_change date="2011-11-14T04:00:49.430-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5890 - modified vulnerabilities which check the version of file adamdsa.dll" date="2013-12-18T16:36:00.218-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-18T16:44:40.876-05:00">INTERIM</status_change>
            <status_change date="2014-01-06T04:00:47.950-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:89195 - bulletin MS14-016, for the month of Mar 2014." date="2014-03-18T14:40:00.553-04:00">
              <contributor organization="SecPod Technologies">Pooja Shetty</contributor>
            </modified>
            <status_change date="2014-03-18T14:42:04.593-04:00">INTERIM</status_change>
            <status_change date="2014-04-07T04:06:55.345-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for Windows 2000 and Vulnerable file">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="NTDS Service is installed" test_ref="oval:org.mitre.oval:tst:42615"/>
          <criterion comment="Ntdsa.dll version is less than 5.0.2195.7313" test_ref="oval:org.mitre.oval:tst:10398"/>
          <criterion comment="the system is being used as AD - DomainRole is 4 or 5" test_ref="oval:org.mitre.oval:tst:10696"/>
        </criteria>
        <criteria operator="AND" comment="Check for Vulnerable OS and file">
          <criteria operator="OR" comment="Check for Windows 2003 (x86/x64)">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
          </criteria>
          <criteria operator="OR" comment="Active Directory or ADAM">
            <criteria operator="AND" comment="Check for Vulnerable file">
              <criterion comment="NTDS Service is installed" test_ref="oval:org.mitre.oval:tst:42615"/>
              <criterion comment="the system is being used as AD - DomainRole is 4 or 5" test_ref="oval:org.mitre.oval:tst:10696"/>
              <criterion comment="ntdsa.dll version is less than 5.2.3790.4568" test_ref="oval:org.mitre.oval:tst:11019"/>
            </criteria>
            <criteria operator="AND" comment="Vulnerable ADAM">
              <criterion comment="Check if ADAM service is installed" test_ref="oval:org.mitre.oval:tst:89195"/>
              <criterion comment="adamdsa.dll version is less than 1.1.3790.4569" test_ref="oval:org.mitre.oval:tst:10537"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for Windows 2003 (ia64) and Vulnerable file">
          <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          <criterion comment="NTDS Service is installed" test_ref="oval:org.mitre.oval:tst:42615"/>
          <criterion comment="the system is being used as AD - DomainRole is 4 or 5" test_ref="oval:org.mitre.oval:tst:10696"/>
          <criterion comment="ntdsa.dll version is less than 5.2.3790.4568" test_ref="oval:org.mitre.oval:tst:11019"/>
        </criteria>
        <criteria operator="AND" comment="Check for Vulnerable OS and file">
          <criteria operator="OR" comment="Check for Windows XP (x86/x64)">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          </criteria>
          <criterion comment="Check if ADAM service is installed" test_ref="oval:org.mitre.oval:tst:89195"/>
          <criterion comment="adamdsa.dll version is less than 1.1.3790.4569" test_ref="oval:org.mitre.oval:tst:10537"/>
        </criteria>
        <criteria operator="AND" comment="Check for Vulnerable OS and file">
          <criteria operator="OR" comment="Check for Windows 2008 (x86/x64)">
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criteria operator="AND" comment="Check for Domain Role and vulnerable file">
            <criterion comment="the system is being used as AD - DomainRole is 4 or 5" test_ref="oval:org.mitre.oval:tst:10696"/>
            <criteria operator="OR" comment="Check for file GDR or LDR">
              <criterion comment="ntdsai.dll version is less than 6.0.6001.18281" test_ref="oval:org.mitre.oval:tst:10858"/>
              <criteria operator="AND" comment="Check for LDR">
                <criterion comment="ntdsai.dll version is less than 6.0.6001.22461" test_ref="oval:org.mitre.oval:tst:11031"/>
                <criterion comment="ntdsai.dll is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:10907"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for Vulnerable OS and file">
          <criteria operator="OR" comment="Check for Windows 2008 (x86/x64) SP2">
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
          </criteria>
          <criteria operator="AND" comment="Check for Domain Role and vulnerable file">
            <criterion comment="the system is being used as AD - DomainRole is 4 or 5" test_ref="oval:org.mitre.oval:tst:10696"/>
            <criteria operator="OR" comment="Check for file GDR or LDR">
              <criterion comment="ntdsai.dll version is less than 6.0.6002.18058" test_ref="oval:org.mitre.oval:tst:11092"/>
              <criteria operator="AND" comment="Check for LDR">
                <criterion comment="ntdsai.dll version is less than 6.0.6002.22162" test_ref="oval:org.mitre.oval:tst:10845"/>
                <criterion comment="ntdsai.dll is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10980"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5886" version="7" class="vulnerability">
      <metadata>
        <title>URL Parsing Cross-Domain Information Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Outlook Express</product>
          <product>Microsoft Mail</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1448" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1448"/>
        <description>The MHTML protocol handler in a component of Microsoft Outlook Express 5.5 SP2 and 6 through SP1, and Windows Mail, does not assign the correct Internet Explorer Security Zone to UNC share pathnames, which allows remote attackers to bypass intended access restrictions and read arbitrary files via an mhtml: URI in conjunction with a redirection, aka "URL Parsing Cross-Domain Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-13T09:28:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-08-14T15:02:47.644-04:00">DRAFT</status_change>
            <status_change date="2008-09-01T04:01:14.157-04:00">INTERIM</status_change>
            <status_change date="2008-09-22T04:00:36.238-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8459 - def:5886, Added LDR criteria for WinVista &amp; 2008. tst:8248, tst:8366, tst:8459, tst:8947, tst:8951, tst:9051, tst:9171, tst:9185 comments corrected." date="2011-11-22T11:36:00.281-05:00">
              <contributor organization="SecPod Technologies">Pradeep R B</contributor>
            </modified>
            <status_change date="2011-11-22T11:39:24.355-05:00">INTERIM</status_change>
            <status_change date="2011-12-12T04:10:19.758-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5886 - Correcting incorrect references to 64-bit Itanium XP." date="2012-08-23T17:47:00.168-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-08-23T17:52:55.531-04:00">INTERIM</status_change>
            <status_change date="2012-09-10T04:01:03.660-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5886 - extended definitions of OS are without SP checks" date="2014-07-28T17:39:00.892-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:41:16.238-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:04.051-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Microsoft Outlook Express 5.5 SP2 on Win 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Outlook Express 5.5 SP2 is installed." definition_ref="oval:org.mitre.oval:def:504"/>
          <criterion comment="the version of Inetcomm.dll is less than 5.50.4990.2500" test_ref="oval:org.mitre.oval:tst:8947"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Outlook Express 6 SP1 on Win 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Outlook Express 6 SP1 is installed." definition_ref="oval:org.mitre.oval:def:488"/>
          <criterion comment="the version of Inetcomm.dll is less than 6.0.2800.1933" test_ref="oval:org.mitre.oval:tst:8366"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Outlook Express 6">
          <extend_definition comment="Microsoft Outlook Express 6.0 for Windows XP/2003 is installed" definition_ref="oval:org.mitre.oval:def:208"/>
          <criteria operator="OR" comment="OS Check">
            <criteria operator="AND" comment="Vulnerable Win XP">
              <extend_definition comment="Microsoft Windows XP is installed" definition_ref="oval:org.mitre.oval:def:105"/>
              <criterion comment="the version of Inetcomm.dll is less than 6.0.2900.3350" test_ref="oval:org.mitre.oval:tst:8951"/>
            </criteria>
            <criteria operator="AND" comment="Vulnerable Win XP">
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              <criterion comment="the version of Inetcomm.dll is less than 6.0.2900.5579" test_ref="oval:org.mitre.oval:tst:8248"/>
            </criteria>
            <criteria operator="AND" comment="Vulnerable Win XP X64/win 2003">
              <criteria operator="OR" comment="Win XP X64/win 2003">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="the version of Inetcomm.dll is less than 6.0.3790.3168" test_ref="oval:org.mitre.oval:tst:9171"/>
            </criteria>
            <criteria operator="AND" comment="Vulnerable Win XP X64/win 2003">
              <criteria operator="OR" comment="Win XP X64/win 2003">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
              </criteria>
              <criterion comment="the version of Inetcomm.dll is less than 6.0.3790.4325" test_ref="oval:org.mitre.oval:tst:9185"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows Mail">
          <extend_definition comment="Microsoft Windows Mail is installed" definition_ref="oval:org.mitre.oval:def:2058"/>
          <criteria operator="OR" comment="OS Check">
            <criteria operator="AND" comment="Vulnerable Windows Vista 32-bit or 64-bit">
              <criteria operator="OR" comment="Windows Vista 32-bit or 64-bit">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
              </criteria>
              <criteria operator="OR" comment="Check for LDR/GDR">
                <criterion comment="the version of Inetcomm.dll is less than 6.0.6000.16669" test_ref="oval:org.mitre.oval:tst:8459"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if version of Inetcomm.dll is greater than or equal to 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:77412"/>
                  <criterion comment="Check if version of Inetcomm.dll is less than 6.0.6000.20810" test_ref="oval:org.mitre.oval:tst:77328"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Vulnerable Windows Vista/Win server 2008">
              <criteria operator="OR" comment="Windows Vista/Win server 2008">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
              </criteria>
              <criteria operator="OR" comment="Check for LDR/GDR">
                <criterion comment="the version of Inetcomm.dll is less than 6.0.6001.18049" test_ref="oval:org.mitre.oval:tst:9051"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="the version of Inetcomm.dll is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:11476"/>
                  <criterion comment="Check if version of Inetcomm.dll is less than 6.0.6001.22154" test_ref="oval:org.mitre.oval:tst:77450"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5863" version="1" class="vulnerability">
      <metadata>
        <title>SMB Buffer Overflow Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4834" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4834"/>
        <description>Buffer overflow in SMB in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via malformed values of unspecified "fields inside the SMB packets" in an NT Trans request, aka "SMB Buffer Overflow Remote Code Execution Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-01-13T13:07:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2009-01-20T17:42:24.575-05:00">DRAFT</status_change>
            <status_change date="2009-02-09T04:00:07.323-05:00">INTERIM</status_change>
            <status_change date="2009-03-02T04:00:09.079-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Srv.sys version is less than 5.0.2195.7222" test_ref="oval:org.mitre.oval:tst:9419"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="Srv.sys version is less than 5.1.2600.3491" test_ref="oval:org.mitre.oval:tst:9449"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Srv.sys version is less than 5.1.2600.5725" test_ref="oval:org.mitre.oval:tst:9588"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="Srv.sys version is less than 5.2.3790.3260" test_ref="oval:org.mitre.oval:tst:9297"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <criterion comment="Srv.sys version is less than 5.2.3790.4425" test_ref="oval:org.mitre.oval:tst:9603"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:4386"/>
            <extend_definition comment="Microsoft Windows XP x64 Edition SP1 is installed" definition_ref="oval:org.mitre.oval:def:720"/>
          </criteria>
          <criterion comment="Srv.sys version is less than 5.2.3790.3260" test_ref="oval:org.mitre.oval:tst:9297"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          </criteria>
          <criterion comment="Srv.sys version is less than 5.2.3790.4425" test_ref="oval:org.mitre.oval:tst:9603"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5861" version="1" class="vulnerability">
      <metadata>
        <title>IIS 5.0 WebDAV Authentication Bypass Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server 5.0</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1122" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1122"/>
        <description>The WebDAV extension in Microsoft Internet Information Services (IIS) 5.0 on Windows 2000 SP4 does not properly decode URLs, which allows remote attackers to bypass authentication, and possibly read or create files, via a crafted HTTP request, aka "IIS 5.0 WebDAV Authentication Bypass Vulnerability," a different vulnerability than CVE-2009-1535.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-06-15T14:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <modified comment="updated file version" date="2009-06-17T14:53:00.273-04:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </modified>
            <modified comment="changed operator to &quot;less than&quot;" date="2009-06-17T14:53:00.193-04:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2009-06-17T15:28:08.091-04:00">DRAFT</status_change>
            <status_change date="2009-07-06T04:00:27.484-04:00">INTERIM</status_change>
            <status_change date="2009-07-21T07:45:57.357-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
        <extend_definition comment="Microsoft IIS 5.0 is installed" definition_ref="oval:org.mitre.oval:def:731"/>
        <criterion comment="the version of httpext.dll is less than 5.0.2195.7290" test_ref="oval:org.mitre.oval:tst:9836"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5847" version="1" class="vulnerability">
      <metadata>
        <title>MSXML Header Request Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Office 2003</product>
          <product>Microsoft Office 2008</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4033" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4033"/>
        <description>Cross-domain vulnerability in Microsoft XML Core Services 3.0 through 6.0, as used in Microsoft Expression Web, Office, Internet Explorer, and other products, allows remote attackers to obtain sensitive information from another domain and corrupt the session state via HTTP request header fields, as demonstrated by the Transfer-Encoding field, aka "MSXML Header Request Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-11-19T14:19:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <modified comment="Changed the location of MSXML5.dll, which is installed as a part of Office 2003 and Office 2007" date="2008-11-19T10:37:00.716-05:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2008-11-19T10:52:29.205-05:00">DRAFT</status_change>
            <status_change date="2008-12-08T04:00:59.189-05:00">INTERIM</status_change>
            <status_change date="2008-12-29T04:00:28.912-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criteria operator="OR">
          <criteria operator="AND">
            <extend_definition comment="Microsoft XML Core Services 3 is installed" definition_ref="oval:org.mitre.oval:def:415"/>
            <criterion comment="msxml3.dll version is less than 8.100.1048.0" test_ref="oval:org.mitre.oval:tst:9071"/>
          </criteria>
          <criteria operator="AND">
            <extend_definition comment="Microsoft XML Core Services 4 is installed" definition_ref="oval:org.mitre.oval:def:1002"/>
            <criterion comment="msxml4.dll version is less than 4.20.9870.0" test_ref="oval:org.mitre.oval:tst:9539"/>
          </criteria>
          <criteria operator="AND">
            <extend_definition comment="Microsoft XML Core Services 5 is installed" definition_ref="oval:org.mitre.oval:def:493"/>
            <criterion comment="msxml5.dll version is less than 5.20.1087.0" test_ref="oval:org.mitre.oval:tst:9234"/>
          </criteria>
          <criteria operator="AND">
            <extend_definition comment="Microsoft XML Core Services 6 is installed" definition_ref="oval:org.mitre.oval:def:454"/>
            <criterion comment="msxml6.dll version is less than 6.20.1099.0" test_ref="oval:org.mitre.oval:tst:9530"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5842" version="8" class="vulnerability">
      <metadata>
        <title>Null Truncation in X.509 Common Name Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft ASN.1 Library</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2510" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2510"/>
        <description>The CryptoAPI component in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, as used by Internet Explorer and other applications, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, aka "Null Truncation in X.509 Common Name Vulnerability," a related issue to CVE-2009-2408.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-13T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-10-22T17:37:06.961-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:26.396-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:11.936-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5842 - LDR version criteria are added for Vista &amp; 2008, and also added non-root criterion comments" date="2011-10-04T13:16:00.750-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-10-04T13:19:19.322-04:00">INTERIM</status_change>
            <status_change date="2011-10-24T04:00:14.969-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:46.665-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:46.665-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:06.824-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5842 - extended definitions of OS are without SP checks" date="2014-07-28T17:49:00.293-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:51:14.011-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:03.122-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <criterion comment="the version of msasn1.dll is less than 5.0.2195.7334" test_ref="oval:org.mitre.oval:tst:10655"/>
        </criteria>
        <criteria operator="AND" comment="Windows XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="the version of msasn1.dll is less than 5.1.2600.3624" test_ref="oval:org.mitre.oval:tst:10905"/>
        </criteria>
        <criteria operator="AND" comment="Windows XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="the version of msasn1.dll is less than 5.1.2600.5875" test_ref="oval:org.mitre.oval:tst:10731"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64, Windows Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Operating System Check">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <criterion comment="the version of msasn1.dll is less than 5.2.3790.4584" test_ref="oval:org.mitre.oval:tst:10013"/>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64">
          <criteria operator="OR" comment="Operating System Check">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of msasn1.dll is less than 6.0.6000.16922" test_ref="oval:org.mitre.oval:tst:10512"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of msasn1.dll is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:44028"/>
              <criterion comment="the version of msasn1.dll is less than 6.0.6000.21122" test_ref="oval:org.mitre.oval:tst:43659"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64, Windows Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Operating System Check">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of msasn1.dll is less than 6.0.6001.18326" test_ref="oval:org.mitre.oval:tst:10835"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of msasn1.dll is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:44222"/>
              <criterion comment="the version of msasn1.dll is less than 6.0.6001.22515" test_ref="oval:org.mitre.oval:tst:43926"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows Vista x86/x64, Windows Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Operating System Check">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of msasn1.dll is less than 6.0.6002.18106" test_ref="oval:org.mitre.oval:tst:10818"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of msasn1.dll is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:44044"/>
              <criterion comment="the version of msasn1.dll is less than 6.0.6002.22218" test_ref="oval:org.mitre.oval:tst:44105"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows 7 x86/x64, Windows Server 2008 R2 x86/x64/ia64">
          <criteria operator="OR" comment="Operating System Check">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of msasn1.dll is less than 6.1.7600.16415" test_ref="oval:org.mitre.oval:tst:10587"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of msasn1.dll is greater than or equal 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:10901"/>
              <criterion comment="the version of msasn1.dll is less than 6.1.7600.20518" test_ref="oval:org.mitre.oval:tst:10706"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:584" version="3" class="vulnerability">
      <metadata>
        <title>Mozilla IDN heap overrun using soft-hyphens</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2871" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2871"/>
        <description>Buffer overflow in the International Domain Name (IDN) support in Mozilla Firefox 1.0.6 and earlier, and Netscape 8.0.3.3 and 7.2, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a hostname with all "soft" hyphens (character 0xAD), which is not properly handled by the NormalizeIDN call in nsStandardURL::BuildNormalizedSpec.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-11T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-12T10:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:2367" date="2007-02-26T08:32:00.241-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-26T08:32:39.060-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:2370" date="2007-03-06T07:46:00.064-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:17:21.368-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:1444" date="2007-04-23T12:05:00.911-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:19:58.657-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:1445" date="2007-04-23T12:05:00.720-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:11:06.815-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Suite version 1.7.10 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.10 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2535"/>
          <criterion comment="Mozilla Suite version 1.7.10 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2534"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.6 or earlier is installed">
          <criterion comment="Firefox version 1.0.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2533"/>
          <criterion comment="Mozilla Firefox version 1.0.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2532"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5829" version="3" class="vulnerability">
      <metadata>
        <title>HTML Rendering Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Internet Explorer 5.01</product>
          <product>Microsoft Internet Explorer 6</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4261" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4261"/>
        <description>Stack-based buffer overflow in Microsoft Internet Explorer 5.01 SP4, 6 SP1 on Windows 2000, and 6 on Windows XP and Server 2003 does not properly handle extraneous data associated with an object embedded in a web page, which allows remote attackers to execute arbitrary code via crafted HTML tags that trigger memory corruption, aka "HTML Rendering Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-12-09T13:31:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-12-12T16:42:48.259-05:00">DRAFT</status_change>
            <status_change date="2008-12-29T04:00:27.080-05:00">INTERIM</status_change>
            <status_change date="2009-01-19T04:00:11.513-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5829 - Submission from SecPod" date="2011-11-14T13:25:00.552-05:00">
              <contributor organization="SecPod Technologies">Pradeep R B</contributor>
            </modified>
            <status_change date="2011-11-14T13:28:26.369-05:00">INTERIM</status_change>
            <status_change date="2011-12-05T04:00:32.324-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for Vulnerable Windows 2000 SP4 and Mshtml.dll version">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="Mshtml.dll version is less than 5.0.3870.1500" test_ref="oval:org.mitre.oval:tst:9553"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable IE 6">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="Vulnerable Versions">
            <criteria operator="AND" comment="Check for Vulnerable Windows 2000 SP4 and Mshtml.dll version">
              <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
              <criterion comment="Mshtml.dll version is less than 6.0.2800.1617" test_ref="oval:org.mitre.oval:tst:9607"/>
            </criteria>
            <criteria operator="AND" comment="Check for Vulnerable Windows XP (x86) SP2 and Mshtml.dll version">
              <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
              <criterion comment="Mshtml.dll version is less than 6.0.2900.3462" test_ref="oval:org.mitre.oval:tst:9581"/>
            </criteria>
            <criteria operator="AND" comment="Check for Vulnerable Windows XP (x86) SP3 and Mshtml.dll version">
              <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
              <criterion comment="Mshtml.dll version is less than 6.0.2900.5694" test_ref="oval:org.mitre.oval:tst:9271"/>
            </criteria>
            <criteria operator="AND" comment="Check for Vulnerable Server 2003 SP1/2003(ia-64) SP1/XP (x64) and Mshtml.dll version">
              <criteria operator="OR" comment="Check for Vulnerable Server 2003 SP1/2003(ia-64)/XP (x64)">
                <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
                <extend_definition comment="Microsoft Windows XP Professional x64 Edition SP1 is installed" definition_ref="oval:org.mitre.oval:def:720"/>
                <extend_definition comment="Microsoft Windows Server 2003 SP1 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
                <extend_definition comment="Microsoft Windows Server 2003 SP1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:4386"/>
              </criteria>
              <criterion comment="Mshtml.dll version is less than 6.0.3790.3229" test_ref="oval:org.mitre.oval:tst:8743"/>
            </criteria>
            <criteria operator="AND" comment="Check for Vulnerable Server 2003 SP2/2003 SP2(ia-64) SP2/XP SP2(x64) and Mshtml.dll version">
              <criteria operator="OR" comment="Check for Vulnerable Server 2003 SP2/2003 SP2(ia-64) SP2/XP SP2(x64)">
                <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
                <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
                <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
              </criteria>
              <criterion comment="Mshtml.dll version is less than 6.0.3790.4392" test_ref="oval:org.mitre.oval:tst:9508"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5820" version="5" class="vulnerability">
      <metadata>
        <title>HTML Object Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2254" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2254"/>
        <description>Microsoft Internet Explorer 6 and 7 accesses uninitialized memory, which allows remote attackers to cause a denial of service (crash) and execute arbitrary code via unknown vectors, aka "HTML Object Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-13T09:28:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-08-14T15:02:52.988-04:00">DRAFT</status_change>
            <status_change date="2008-09-01T04:01:09.720-04:00">INTERIM</status_change>
            <status_change date="2008-09-22T04:00:32.748-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:9018 - Included LDR support &amp; added new state to match correct version." date="2011-10-25T14:07:00.717-04:00">
              <contributor organization="SecPod Technologies">Pooja Shetty</contributor>
            </modified>
            <status_change date="2011-10-25T14:12:05.827-04:00">INTERIM</status_change>
            <status_change date="2011-11-14T04:00:46.553-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5820 - extended definitions of OS are without SP checks" date="2014-07-28T17:39:00.892-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:41:15.441-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:02.860-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win 2K + IE6 vulnerable version">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1613" test_ref="oval:org.mitre.oval:tst:8781"/>
        </criteria>
        <criteria operator="AND" comment="Win XP + IE 6">
          <extend_definition comment="Microsoft Windows XP is installed" definition_ref="oval:org.mitre.oval:def:105"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3395" test_ref="oval:org.mitre.oval:tst:8921"/>
        </criteria>
        <criteria operator="AND" comment="Win XP + IE 6">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5626" test_ref="oval:org.mitre.oval:tst:9128"/>
        </criteria>
        <criteria operator="AND" comment="Win XP /  Win 2K3 + IE 7">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="Win XP / Win 2K3">
            <extend_definition comment="Microsoft Windows XP is installed" definition_ref="oval:org.mitre.oval:def:105"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR / GDR">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16705" test_ref="oval:org.mitre.oval:tst:9018"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Check if the version mshtml.dll is less than 7.0.6000.20861" test_ref="oval:org.mitre.oval:tst:44137"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 2K3 / Win XP X64 and IE 6">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.3167" test_ref="oval:org.mitre.oval:tst:8958"/>
          <criteria operator="OR" comment="Win 2K3 / Win XP X64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win XP X64 / Win 2K3">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4324" test_ref="oval:org.mitre.oval:tst:8988"/>
          <criteria operator="OR" comment="Win 2K3 / Win XP X64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win Vista and IE7">
          <extend_definition comment="Microsoft Windows Vista is installed" definition_ref="oval:org.mitre.oval:def:228"/>
          <criteria operator="OR" comment="Check for LDR and GDR">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16711" test_ref="oval:org.mitre.oval:tst:8163"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.20868" test_ref="oval:org.mitre.oval:tst:44258"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
        </criteria>
        <criteria operator="AND" comment="Win Vista / Win 2K8 and IE7">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="Win Vista/ Win 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR /GDR">
            <criterion comment="Mshtml.dll version is less than 7.0.6001.18099" test_ref="oval:org.mitre.oval:tst:9108"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Mshtml.dll version is greater than or equal to 7.0.6001.22000" test_ref="oval:org.mitre.oval:tst:42152"/>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6001.22212" test_ref="oval:org.mitre.oval:tst:44416"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:582" version="1" class="vulnerability">
      <metadata>
        <title>MSJava Applet CODEBASE File Access Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Virtual Machine (VM)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1258" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1258"/>
        <description>Two vulnerabilities in Microsoft Virtual Machine (VM) up to and including build 5.0.3805, as used in Internet Explorer and other applications, allow remote attackers to read files via a Java applet with a spoofed location in the CODEBASE parameter in the APPLET tag, possibly due to a parsing error.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the version of msjava.dll is less than 5.0.3809.0" negate="false" test_ref="oval:org.mitre.oval:tst:2536"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5815" version="6" class="vulnerability">
      <metadata>
        <title>Print Spooler Read File Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0229" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0229"/>
        <description>The Windows Printing Service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 allows local users to read arbitrary files via a crafted separator page, aka "Print Spooler Read File Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-06-09T14:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-06-15T17:07:12.131-04:00">DRAFT</status_change>
            <status_change date="2009-07-06T04:00:25.470-04:00">INTERIM</status_change>
            <status_change date="2009-07-21T07:45:56.284-04:00">ACCEPTED</status_change>
            <modified comment="Changed operation attribute to 'greater than or equals'" date="2010-02-10T13:05:00.517-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2010-02-10T13:05:54.751-05:00">INTERIM</status_change>
            <modified comment="Changed operation attribute to 'greater than or equals'" date="2010-02-10T13:05:00.923-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2010-03-01T04:00:03.530-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5815 - Modified GDR/LDR service branch format to read easier, removed duplicate, and updated extended def for Vista." date="2011-01-31T14:13:00.964-05:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-01-31T14:14:24.136-05:00">INTERIM</status_change>
            <status_change date="2011-02-21T04:00:54.676-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5160 - contains tests with modified comments and all dependences" date="2014-02-13T12:19:00.287-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:22:59.586-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:11.149-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable on Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Win32spl.dll version is less than 5.0.2195.7266" test_ref="oval:org.mitre.oval:tst:9847"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows XP x86 SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="Localspl.dll version is less than 5.1.2600.3569" test_ref="oval:org.mitre.oval:tst:9961"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows XP x86 SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Localspl.dll version is less than 5.1.2600.5809" test_ref="oval:org.mitre.oval:tst:9871"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="Localspl.dll version is less than 5.2.3790.4509" test_ref="oval:org.mitre.oval:tst:10030"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Vista x86/x64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Localspl.dll version is less than 6.0.6000.16850" test_ref="oval:org.mitre.oval:tst:9868"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Localspl.dll version is less than 6.0.6000.21045" test_ref="oval:org.mitre.oval:tst:9990"/>
              <criterion comment="Localspl.dll version is greater than 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9895"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Vista x86/x64 SP1, all Server 2008 x86/x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Localspl.dll version is less than 6.0.6001.18247" test_ref="oval:org.mitre.oval:tst:9461"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Localspl.dll version is less than 6.0.6001.22417" test_ref="oval:org.mitre.oval:tst:10052"/>
              <criterion comment="Localspl.dll version is greater than 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9965"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Vista x86/x64 SP2, Server 2008 x86/64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Localspl.dll version is less than 6.0.6002.18024" test_ref="oval:org.mitre.oval:tst:9971"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Localspl.dll version is less than 6.0.6002.22120" test_ref="oval:org.mitre.oval:tst:9717"/>
              <criterion comment="Localspl.dll version is greater than 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:9903"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5805" version="5" class="vulnerability">
      <metadata>
        <title>Hierarchical FlexGrid Control Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Visual Basic 6.0</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4254" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4254"/>
        <description>Multiple integer overflows in the Hierarchical FlexGrid ActiveX control (mshflxgd.ocx) in Microsoft Visual Basic 6.0 and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 allow remote attackers to execute arbitrary code via crafted (1) Rows and (2) Cols properties to the (a) ExpandAll and (b) CollapseAll methods, related to access of incorrectly initialized objects and corruption of the "system state," aka "Hierarchical FlexGrid Control Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-12-09T13:31:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-12-12T16:42:48.769-05:00">DRAFT</status_change>
            <status_change date="2008-12-29T04:00:26.236-05:00">INTERIM</status_change>
            <status_change date="2009-01-19T04:00:11.106-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5805 - updated by including Visual FoxPro Inventory criteria" date="2011-11-14T13:22:00.233-05:00">
              <contributor organization="SecPod Technologies">Pradeep R B</contributor>
            </modified>
            <status_change date="2011-11-14T13:23:34.810-05:00">INTERIM</status_change>
            <status_change date="2011-12-05T04:00:31.932-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5805 - New inventory definition for VB6, and updates to definitions incorrectly checking VBA inventory instead of VB6." date="2012-10-25T16:38:00.742-04:00">
              <contributor organization="SecPod Technologies">Pradeep R B</contributor>
            </modified>
            <status_change date="2012-10-25T16:58:26.688-04:00">INTERIM</status_change>
            <status_change date="2012-11-12T04:00:34.005-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Vulnerable Visual Basic 6.0 or VisualFoxPro">
          <extend_definition comment="Microsoft Visual FoxPro is installed" definition_ref="oval:org.mitre.oval:def:14198"/>
          <extend_definition comment="Microsoft Visual Basic 6.0 is installed" definition_ref="oval:org.mitre.oval:def:15369"/>
        </criteria>
        <criterion comment="Mscomct2.ocx version is less than 6.1.98.12" test_ref="oval:org.mitre.oval:tst:9209"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5798" version="3" class="vulnerability">
      <metadata>
        <title>"SITE SET TRANSFERPROGRESS ON" FTP Command Denial of Service Vulnerability in Rhino Software Serv-U</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Rhino Software Serv-U</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3655" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3655"/>
        <description>Rhino Software Serv-U 7.0.0.1 through 8.2.0.3 allows remote attackers to cause a denial of service (server crash) via unspecified vectors related to the "SITE SET TRANSFERPROGRESS ON" FTP command.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-25T18:28:46">
              <contributor organization="SecPod Technologies">Sharath S</contributor>
            </submitted>
            <status_change date="2009-11-25T13:47:55.853-05:00">DRAFT</status_change>
            <status_change date="2009-12-14T04:00:05.754-05:00">INTERIM</status_change>
            <status_change date="2010-01-04T04:01:39.045-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:175 - Removed the trailing \ from all local_variables that are used as paths in a file_object" date="2011-08-03T08:25:00.425-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-08-03T08:26:38.713-04:00">INTERIM</status_change>
            <status_change date="2011-08-22T04:01:09.581-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Rhino Software Serv-U is installed" definition_ref="oval:org.mitre.oval:def:5875"/>
        <criterion comment="Test for Rhino Software Serv-U version is greater than or equal to 7.0.0.1" test_ref="oval:org.mitre.oval:tst:10729"/>
        <criterion comment="Test for Rhino Software Serv-U version is less than or equal to 8.2.0.3" test_ref="oval:org.mitre.oval:tst:11089"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5875" version="1" class="inventory">
      <metadata>
        <title>Rhino Software Serv-U is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Rhino Software Serv-U</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:rhinosoft:serv-u"/>
        <description>The operating system having Rhino Software Serv-U installation.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-25T18:28:46">
              <contributor organization="SecPod Technologies">Sharath S</contributor>
            </submitted>
            <status_change date="2009-11-25T13:47:55.553-05:00">DRAFT</status_change>
            <status_change date="2009-12-14T04:00:06.417-05:00">INTERIM</status_change>
            <status_change date="2010-01-04T04:01:40.248-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
        </criteria>
        <criterion comment="Rhino Software Serv-U is installed" test_ref="oval:org.mitre.oval:tst:11147"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5794" version="5" class="vulnerability">
      <metadata>
        <title>Masked Edit Control Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Visual Basic 6.0</product>
          <product>Microsoft Visual FoxPro</product>
          <product>Microsoft Visual Studio .NET 2002</product>
          <product>Microsoft Visual Studio .NET 2003</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3704" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3704"/>
        <description>Heap-based buffer overflow in the MaskedEdit ActiveX control in Msmask32.ocx 6.0.81.69, and possibly other versions before 6.0.84.18, in Microsoft Visual Studio 6.0, Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 allows remote attackers to execute arbitrary code via a long Mask parameter, related to not "validating property values with boundary checks," as exploited in the wild in August 2008, aka "Masked Edit Control Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-12-09T13:31:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-12-12T16:42:49.009-05:00">DRAFT</status_change>
            <status_change date="2008-12-29T04:00:25.494-05:00">INTERIM</status_change>
            <status_change date="2009-01-19T04:00:10.644-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5794 - updated by including Visual FoxPro Inventory criteria" date="2011-11-14T13:22:00.233-05:00">
              <contributor organization="SecPod Technologies">Pradeep R B</contributor>
            </modified>
            <status_change date="2011-11-14T13:23:36.384-05:00">INTERIM</status_change>
            <status_change date="2011-12-05T04:00:31.514-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5794 - New inventory definition for VB6, and updates to definitions incorrectly checking VBA inventory instead of VB6." date="2012-10-25T16:38:00.742-04:00">
              <contributor organization="SecPod Technologies">Pradeep R B</contributor>
            </modified>
            <status_change date="2012-10-25T16:58:29.715-04:00">INTERIM</status_change>
            <status_change date="2012-11-12T04:00:33.420-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Visual Studio .NET 2002 SP1 /2003 SP1">
          <criteria operator="OR" comment="Visual Studio .NET 2002 SP1 /2003 SP1">
            <extend_definition comment="Microsoft Visual Studio .NET 2002 SP1 is installed" definition_ref="oval:org.mitre.oval:def:981"/>
            <extend_definition comment="Microsoft Visual Studio .NET 2003 SP1 is installed" definition_ref="oval:org.mitre.oval:def:168"/>
          </criteria>
          <criterion comment="Mschrt20.ocx version is less than 6.1.98.12" test_ref="oval:org.mitre.oval:tst:9283"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Visual Basic 6.0 or VisualFoxPro">
          <criteria operator="OR" comment="Visual Basic 6.0 or VisualFoxPro">
            <extend_definition comment="Microsoft Visual FoxPro is installed" definition_ref="oval:org.mitre.oval:def:14198"/>
            <extend_definition comment="Microsoft Visual Basic 6.0 is installed" definition_ref="oval:org.mitre.oval:def:15369"/>
          </criteria>
          <criterion comment="Mscomct2.ocx version is less than 6.1.98.12" test_ref="oval:org.mitre.oval:tst:9209"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5793" version="1" class="vulnerability">
      <metadata>
        <title>MSXML Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0099" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0099"/>
        <description>Race condition in the msxml3 module in Microsoft XML Core Services 3.0, as used in Internet Explorer 6 and other applications, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via many nested tags in an XML document in an IFRAME, when synchronous document rendering is frequently disrupted with asynchronous events, as demonstrated using a JavaScript timer, which can trigger NULL pointer dereferences or memory corruption, aka "MSXML Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-11-19T14:19:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-11-19T10:55:30.493-05:00">DRAFT</status_change>
            <status_change date="2008-12-08T04:00:57.933-05:00">INTERIM</status_change>
            <status_change date="2008-12-29T04:00:25.122-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <extend_definition comment="Microsoft XML Core Services 3 is installed" definition_ref="oval:org.mitre.oval:def:415"/>
        <criterion comment="msxml3.dll version is less than 8.100.1048.0" test_ref="oval:org.mitre.oval:tst:9071"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5787" version="3" class="vulnerability">
      <metadata>
        <title>SMB Buffer Underflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4038" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4038"/>
        <description>Buffer underflow in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to execute arbitrary code via a Server Message Block (SMB) request that contains a filename with a crafted length, aka "SMB Buffer Underflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-10-14T13:33:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-10-16T14:02:11.590-04:00">DRAFT</status_change>
            <status_change date="2008-11-03T04:00:19.819-05:00">INTERIM</status_change>
            <status_change date="2008-11-24T04:00:13.678-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5787 - Updated to support Itanium OS &amp; LDR version check." date="2011-10-25T14:18:00.964-04:00">
              <contributor organization="SecPod Technologies">Pooja Shetty</contributor>
            </modified>
            <status_change date="2011-10-25T14:19:47.492-04:00">INTERIM</status_change>
            <status_change date="2011-11-14T04:00:45.764-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win 2K SP4 and vulnerable version of file">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Srv.sys version is less than 5.0.2195.7177" test_ref="oval:org.mitre.oval:tst:9321"/>
        </criteria>
        <criteria operator="AND" comment="Win XP SP2 X86 and vulnerable version of file">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="Srv.sys version is less than 5.1.2600.3436" test_ref="oval:org.mitre.oval:tst:8960"/>
        </criteria>
        <criteria operator="AND" comment="Win XP SP3 X86 and vulnerable version of file">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Srv.sys version is less than 5.1.2600.5671" test_ref="oval:org.mitre.oval:tst:8802"/>
        </criteria>
        <criteria operator="AND" comment="Win XP SP1 X64 / Win 2K3 SP1 and vulnerable file version">
          <criterion comment="Srv.sys version is less than 5.2.3790.3200" test_ref="oval:org.mitre.oval:tst:8930"/>
          <criteria operator="OR" comment="Win XP X64 SP1 / Win 2K3 SP1">
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:4386"/>
            <extend_definition comment="Microsoft Windows XP Professional x64 Edition SP1 is installed" definition_ref="oval:org.mitre.oval:def:720"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win XP SP2 X64 / Win 2K3 SP2 and vulnerable file version">
          <criterion comment="Srv.sys version is less than 5.2.3790.4363" test_ref="oval:org.mitre.oval:tst:9328"/>
          <criteria operator="OR" comment="Win XP X64 SP1 / Win 2K3 SP1">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win Vista and vulnerable file version">
          <criteria operator="OR" comment="Win Vista 32/ 64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/ GDR">
            <criterion comment="Srv.sys version is less than 6.0.6000.16738" test_ref="oval:org.mitre.oval:tst:9031"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Srv.sys version is greater than or equal to 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:8674"/>
              <criterion comment="Check if the version of srv.sys is less than 6.0.6000.20904" test_ref="oval:org.mitre.oval:tst:44020"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 2K8 / Vista SP1 and vulnerable version of file">
          <criteria operator="OR" comment="Win Vista SP1 / Win 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR / GDR">
            <criterion comment="Srv.sys version is less than 6.0.6001.18130" test_ref="oval:org.mitre.oval:tst:9289"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Srv.sys version is greater than or equal to 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9666"/>
              <criterion comment="Check if the version of srv.sys is less than 6.0.6001.22252" test_ref="oval:org.mitre.oval:tst:44358"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5782" version="3" class="vulnerability" deprecated="true">
      <metadata>
        <title>Blended Threat Elevation of Privilege Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2540" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2540"/>
        <description>Apple Safari on Mac OS X, and before 3.1.2 on Windows, does not prompt the user before downloading an object that has an unrecognized content type, which allows remote attackers to place malware into the (1) Desktop directory on Windows or (2) Downloads directory on Mac OS X, and subsequently allows remote attackers to execute arbitrary code on Windows by leveraging an untrusted search path vulnerability in (a) Internet Explorer 7 on Windows XP or (b) the SearchPath function in Windows XP, Vista, and Server 2003 and 2008, aka a "Carpet Bomb" and a "Blended Threat Elevation of Privilege Vulnerability," a different issue than CVE-2008-1032. NOTE: Apple considers this a vulnerability only because the Microsoft products can load application libraries from the desktop and, as of 20080619, has not covered the issue in an advisory for Mac OS X.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-04-14T16:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-04-17T16:45:23.353-04:00">DRAFT</status_change>
            <status_change date="2009-05-04T04:00:19.771-04:00">INTERIM</status_change>
            <status_change date="2009-05-25T04:01:45.687-04:00">ACCEPTED</status_change>
            <modified comment="Removed Microsoft reference" date="2009-06-01T16:05:28.035-04:00">
              <contributor organization="The MITRE Corporation">Brendan Miles</contributor>
            </modified>
            <status_change date="2009-06-08T04:00:48.306-04:00">INTERIM</status_change>
            <status_change date="2009-06-29T04:00:37.252-04:00">ACCEPTED</status_change>
            <status_change date="2010-07-22T10:00:00.000-05:00">DEPRECATED</status_change>
            <modified comment="Deprecating duplicate definition - use def:8509 instead" date="2010-07-22T10:00:00.000-05:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="The version of Secur32.dll is less than 5.0.2195.7244" test_ref="oval:org.mitre.oval:tst:9587"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="The version of Kernel32.dll is less than 5.1.2600.3541" test_ref="oval:org.mitre.oval:tst:10006"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="The version of Kernel32.dll is less than 5.1.2600.5781" test_ref="oval:org.mitre.oval:tst:9945"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP1 is installed" definition_ref="oval:org.mitre.oval:def:720"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:4386"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP1 is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
          </criteria>
          <criterion comment="The version of Kernel32.dll is less than 5.2.3790.3311" test_ref="oval:org.mitre.oval:tst:9886"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="The version of Kernel32.dll is less than 5.2.3790.4480" test_ref="oval:org.mitre.oval:tst:10168"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="the version of Kernel32.dll is greater than or equal 6.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9719"/>
          <criterion comment="The version of Kernel32.dll is less than 6.0.6000.16820" test_ref="oval:org.mitre.oval:tst:10016"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="the version of Kernel32.dll is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9980"/>
          <criterion comment="The version of Kernel32.dll is less than 6.0.6000.21010" test_ref="oval:org.mitre.oval:tst:9775"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of Kernel32.dll is greater than or equal 6.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9932"/>
          <criterion comment="The version of Kernel32.dll is less than 6.0.6001.18215" test_ref="oval:org.mitre.oval:tst:10000"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of Kernel32.dll is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9167"/>
          <criterion comment="The version of Kernel32.dll is less than 6.0.6001.22376" test_ref="oval:org.mitre.oval:tst:9936"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5774" version="3" class="vulnerability">
      <metadata>
        <title>Access Control Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Office SharePoint Server 2007</product>
          <product>Microsoft Search Server 2008</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4032" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4032"/>
        <description>Microsoft Office SharePoint Server 2007 Gold and SP1 and Microsoft Search Server 2008 do not properly perform authentication and authorization for administrative functions, which allows remote attackers to cause a denial of service (server load), obtain sensitive information, and "create scripts that would run in the context of the site" via requests to administrative URIs, aka "Access Control Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-12-10T10:44:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-12-12T16:42:49.941-05:00">DRAFT</status_change>
            <status_change date="2008-12-29T04:00:24.315-05:00">INTERIM</status_change>
            <status_change date="2009-01-19T04:00:10.275-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5774 - Added Search Server 2008 inventory criteria, new object is created for tst:9391 &amp; corrected tst:9391 comment" date="2011-11-14T13:29:00.007-05:00">
              <contributor organization="SecPod Technologies">Pradeep R B</contributor>
            </modified>
            <status_change date="2011-11-14T13:30:54.533-05:00">INTERIM</status_change>
            <status_change date="2011-12-05T04:00:31.168-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Check for Office SharePoint Server 2007 or Search Server 2008">
          <extend_definition comment="Microsoft Office SharePoint Server 2007 is installed." definition_ref="oval:org.mitre.oval:def:2313"/>
          <extend_definition comment="Microsoft Search Server 2008 is installed" definition_ref="oval:org.mitre.oval:def:14104"/>
        </criteria>
        <criterion comment="the version of Mssdmn.exe is less than 12.0.6318.5000" test_ref="oval:org.mitre.oval:tst:9391"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2313" version="12" class="inventory">
      <metadata>
        <title>Microsoft Office SharePoint Server 2007 is installed.</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Office SharePoint Server 2007</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:sharepoint_server:2007"/>
        <description>Microsoft Office SharePoint Server 2007 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-10-10T04:39:42">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-10-11T10:02:51.975-04:00">DRAFT</status_change>
            <status_change date="2007-10-26T10:00:30.934-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:01:08.127-05:00">ACCEPTED</status_change>
            <modified comment="Changed datatype from version to string." date="2008-08-28T13:32:00.278-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2008-08-28T13:44:16.491-04:00">INTERIM</status_change>
            <status_change date="2008-09-15T04:00:21.134-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2313 - Modifications vary from minor OVAL title/description changes to suggesting an alternative CPE name to use." date="2011-09-28T11:29:00.976-04:00">
              <contributor organization="The MITRE Corporation">David Rothenberg</contributor>
            </modified>
            <status_change date="2011-09-28T11:33:38.747-04:00">INTERIM</status_change>
            <status_change date="2011-10-17T04:00:18.536-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:07.072-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:07.072-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:00.785-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:2686 - MS13-084, 085 and 067 bulletins" date="2013-10-23T11:46:00.610-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2013-10-23T11:49:25.573-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:03.519-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:2686 - In some &quot;pattern match&quot; strings added &quot;\&quot; before &quot;.&quot; to clarify if &quot;point&quot; or &quot;any symbol&quot; needed." date="2014-07-28T18:11:00.493-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-28T18:12:36.194-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:26.510-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2313 - removed Microsoft Exchange Server 2003 from inventory" date="2015-06-05T09:04:00.152-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-06-05T09:06:27.662-04:00">INTERIM</status_change>
            <status_change date="2015-06-22T04:00:42.619-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="SharePoint Server 2007 is installed." test_ref="oval:org.mitre.oval:tst:4279"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:14104" version="3" class="inventory">
      <metadata>
        <title>Microsoft Search Server 2008 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Windows 7</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:search_server:2008"/>
        <description>Microsoft Search Server 2008 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-11-08T07:50:11">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-11-14T13:30:42.767-05:00">DRAFT</status_change>
            <status_change date="2011-12-05T04:00:22.448-05:00">INTERIM</status_change>
            <status_change date="2011-12-26T04:01:00.652-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Search Server 2008 is installed" test_ref="oval:org.mitre.oval:tst:77223"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:577" version="10" class="vulnerability">
      <metadata>
        <title>Source Element Cross-Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference ref_id="CVE-2006-3639" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3639" source="CVE"/>
        <description>Microsoft Internet Explorer 5.01 and 6 does not properly identify the originating domain zone when handling redirects, which allows remote attackers to read cross-domain web pages and possibly execute code via unspecified vectors involving a crafted web page, aka "Source Element Cross-Domain Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:31.779-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:45.074-04:00">ACCEPTED</status_change>
            <modified comment="Added an anchor to the regex used to check for Internet Explorer 6." date="2007-01-11T20:38:00.950-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-01-11T20:49:13.232-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:47.502-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:2185 - Anchored regular expression" date="2011-02-22T12:51:00.261-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:52:30.200-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:00:52.992-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:55.704-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:23.944-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:136 - modified comments" date="2014-02-28T15:13:00.247-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-28T15:16:21.099-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:22.694-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:95 - Addressed validation errors and duplicate extended definitions" date="2015-07-13T20:21:00.869-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:25:26.093-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:01:55.593-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Server 2003-Gold">
          <extend_definition comment="Microsoft Windows Server 2003 (x86) Gold is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.554" test_ref="oval:org.mitre.oval:tst:136"/>
        </criteria>
        <criteria comment="XP,SP1 (64-bit) and Server 2003, SP1">
          <criteria operator="OR" comment="Windows XP (64-bit,SP1) or Server 2003 (SP1) is installed">
            <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2759" test_ref="oval:org.mitre.oval:tst:175"/>
        </criteria>
        <criteria comment="IE 6 on Windows XP,SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.2963" test_ref="oval:org.mitre.oval:tst:95"/>
        </criteria>
        <criteria comment="IE 6 on Windows 2000 or XP,SP1 (32-bit)">
          <criteria operator="OR" comment="Win2K,SP4 or XP,SP1 (32-bit) is installed">
            <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
            <extend_definition comment="Microsoft Windows XP SP1 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1561" test_ref="oval:org.mitre.oval:tst:56"/>
        </criteria>
        <criteria comment="IE 5.01,SP4 on Win2k,SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3842.3000" test_ref="oval:org.mitre.oval:tst:106"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5766" version="7" class="vulnerability">
      <metadata>
        <title>Uninitialized Memory Corruption Vulnerability (CVE-2009-2531)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2531" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2531"/>
        <description>Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-2530.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-13T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-10-22T17:36:44.544-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:23.345-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:08.943-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5766 - Modified GDR/LDR service branch format to read easier, removed duplicate, and updated extended def for Vista." date="2011-01-31T14:13:00.402-05:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-01-31T14:13:52.444-05:00">INTERIM</status_change>
            <status_change date="2011-02-21T04:00:53.497-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:25:00.386-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:10.832-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5766 - extended definitions of OS are without SP checks" date="2014-07-28T17:39:00.892-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:41:16.500-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:02.524-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE6/Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1638" test_ref="oval:org.mitre.oval:tst:10604"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on Windows XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3627" test_ref="oval:org.mitre.oval:tst:10771"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on Windows XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5880" test_ref="oval:org.mitre.oval:tst:10838"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on all Windows XP x64, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4589" test_ref="oval:org.mitre.oval:tst:10917"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows XP x86, x64">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16915" test_ref="oval:org.mitre.oval:tst:10949"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.21115" test_ref="oval:org.mitre.oval:tst:10971"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16915" test_ref="oval:org.mitre.oval:tst:10949"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.21115" test_ref="oval:org.mitre.oval:tst:10971"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16916" test_ref="oval:org.mitre.oval:tst:10612"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.21116" test_ref="oval:org.mitre.oval:tst:10668"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows Vista x86/x64, all Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6001.18319" test_ref="oval:org.mitre.oval:tst:10928"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6001.22508" test_ref="oval:org.mitre.oval:tst:10959"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows Vista x86/x64, Server 2008 x86/64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6002.18100" test_ref="oval:org.mitre.oval:tst:10793"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6002.22212" test_ref="oval:org.mitre.oval:tst:10952"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Windows XP x86 SP3 / x64 SP2, Server 2003 x86/x64 , Vista x86/x64 / x86 SP2, Server 2008 x86/x64 / x86/x64 SP2">
          <criteria operator="OR" comment="OS section">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 8.0.6001.18828" test_ref="oval:org.mitre.oval:tst:10824"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
              <criterion comment="Mshtml.dll version is less than 8.0.6001.22918" test_ref="oval:org.mitre.oval:tst:10966"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5764" version="4" class="vulnerability">
      <metadata>
        <title>Integer Overflow in IPP Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1446" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1446"/>
        <description>Integer overflow in the Internet Printing Protocol (IPP) ISAPI extension in Microsoft Internet Information Services (IIS) 5.0 through 7.0 on Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, and Server 2008 allows remote authenticated users to execute arbitrary code via an HTTP POST request that triggers an outbound IPP connection from a web server to a machine operated by the attacker, aka "Integer Overflow in IPP Service Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-10-14T13:33:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-10-16T14:02:12.752-04:00">DRAFT</status_change>
            <status_change date="2008-11-03T04:00:19.107-05:00">INTERIM</status_change>
            <status_change date="2008-11-24T04:00:12.542-05:00">ACCEPTED</status_change>
            <modified comment="Added tests for IIS and Internet Printing installed for 2000, XP and 2003" date="2009-08-01T10:34:28.035-04:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2009-09-14T04:00:17.362-04:00">INTERIM</status_change>
            <status_change date="2009-10-05T04:00:04.494-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5764 - def:5764, Added support for Win2003 IA-64 SP1, SP2 &amp; LDR check on Winvista, 2008" date="2011-11-15T14:53:00.901-05:00">
              <contributor organization="SecPod Technologies">Pradeep R B</contributor>
            </modified>
            <status_change date="2011-11-15T14:56:02.511-05:00">INTERIM</status_change>
            <status_change date="2011-12-05T04:00:30.372-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable IIS subcomponent">
          <criterion comment="IIS subcomponent is installed" test_ref="oval:org.mitre.oval:tst:9823"/>
          <criteria operator="OR" comment="Vulnerable file version">
            <criteria operator="AND" comment="Vulnerable Windows 2000 SP4">
              <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
              <criterion comment="Win32spl.dll version is less than 5.0.2195.7188" test_ref="oval:org.mitre.oval:tst:8834"/>
            </criteria>
            <criteria operator="AND" comment="Vulnerable Windows XP (x86) SP2">
              <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
              <criterion comment="Win32spl.dll version is less than 5.1.2600.3435" test_ref="oval:org.mitre.oval:tst:9281"/>
            </criteria>
            <criteria operator="AND" comment="Vulnerable Windows XP (x86) SP3">
              <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
              <criterion comment="Win32spl.dll version is less than 5.1.2600.5664" test_ref="oval:org.mitre.oval:tst:9352"/>
            </criteria>
            <criteria operator="AND" comment="Vulnerable Windows XP x64 SP1">
              <extend_definition comment="Microsoft Windows XP Professional x64 Edition SP1 is installed" definition_ref="oval:org.mitre.oval:def:720"/>
              <criterion comment="Win32spl.dll version is less than 5.2.3790.3208" test_ref="oval:org.mitre.oval:tst:9001"/>
            </criteria>
            <criteria operator="AND" comment="Vulnerable Windows XP x64 SP2">
              <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
              <criterion comment="Win32spl.dll version is less than 5.2.3790.4371" test_ref="oval:org.mitre.oval:tst:8857"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable IIS subcomponent or Internet Printing subcomponent">
          <criterion comment="Internet Printing subcomponent is installed" test_ref="oval:org.mitre.oval:tst:10769"/>
          <criterion comment="IIS subcomponent is installed" test_ref="oval:org.mitre.oval:tst:9823"/>
          <criteria operator="OR" comment="Vulnerable file version">
            <criteria operator="AND" comment="Vulnerable Windows Server 2003 SP1">
              <criteria operator="OR" comment="Windows Server 2003 SP1">
                <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
                <extend_definition comment="Microsoft Windows Server 2003 SP1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:4386"/>
                <extend_definition comment="Microsoft Windows Server 2003 SP1 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
              </criteria>
              <criterion comment="Win32spl.dll version is less than 5.2.3790.3208" test_ref="oval:org.mitre.oval:tst:9001"/>
            </criteria>
            <criteria operator="AND" comment="Vulnerable Windows Server 2003 SP2">
              <criteria operator="OR" comment="Windows Server 2003 SP2">
                <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
                <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
              </criteria>
              <criterion comment="Win32spl.dll version is less than 5.2.3790.4371" test_ref="oval:org.mitre.oval:tst:8857"/>
            </criteria>
            <criteria operator="AND" comment="Vulnerable Windows Server 2008">
              <criteria operator="OR" comment=" Windows Server 2008">
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for LDR/GDR">
                <criterion comment="Win32spl.dll version is less than 6.0.6001.18119" test_ref="oval:org.mitre.oval:tst:9011"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if version of Win32spl.dll is greater than or equal to 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:77277"/>
                  <criterion comment="Check if version of Win32spl.dll is less than 6.0.6001.22241" test_ref="oval:org.mitre.oval:tst:77375"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Vista">
          <criteria operator="OR" comment="Windows Vista">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criterion comment="Win32spl.dll version is less than 6.0.6000.16728" test_ref="oval:org.mitre.oval:tst:9285"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if version of Win32spl.dll is greater than or equal to 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:77246"/>
              <criterion comment="Check if version of Win32spl.dll is less than 6.0.6000.20893" test_ref="oval:org.mitre.oval:tst:77295"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Vulnerable Windows Vista SP1">
            <criteria operator="OR" comment="Windows Vista SP1">
              <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
              <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            </criteria>
            <criteria operator="OR" comment="Check for LDR/GDR">
              <criterion comment="Win32spl.dll version is less than 6.0.6001.18119" test_ref="oval:org.mitre.oval:tst:9011"/>
              <criteria operator="AND" comment="Check for LDR">
                <criterion comment="Check if version of Win32spl.dll is greater than or equal to 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:77277"/>
                <criterion comment="Check if version of Win32spl.dll is less than 6.0.6001.22241" test_ref="oval:org.mitre.oval:tst:77375"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:575" version="3" class="vulnerability">
      <metadata>
        <title>Windows 2000 Workstation Service Logging Function Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Windows Workstation Service</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0812" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0812"/>
        <description>Stack-based buffer overflow in a logging function for Windows Workstation Service (WKSSVC.DLL) allows remote attackers to execute arbitrary code via RPC calls that cause long entries to be written to a debug log file ("NetSetup.LOG"), as demonstrated using the NetAddAlternateComputerName API.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:1448 - Correction of a filename (Spwmp.dll is replaced by wkssvc.dll as per the bulletin info.) in an object oval:org.mitre.oval:obj:1448 along with comments" date="2011-09-14T12:12:00.927-04:00">
              <contributor organization="SecPod Technologies">Pradeep R B</contributor>
            </modified>
            <status_change date="2011-09-14T12:12:56.922-04:00">INTERIM</status_change>
            <status_change date="2011-10-03T04:00:06.592-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="the version of wkssvc.dll is less than 5.00.2195.6862" negate="false" test_ref="oval:org.mitre.oval:tst:2541"/>
          <criterion comment="the patch q828748 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2540"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the workstation service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2696"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5740" version="7" class="vulnerability">
      <metadata>
        <title>IE v6.0,SP1 SSL Cached Content Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0845" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0845"/>
        <description>Internet Explorer 5.01, 5.5, and 6 does not properly cache SSL content, which allows remote attackers to obtain information or spoof content via a web site with the same host name as the target web site, whose content is cached and reused when the user visits the target web site.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-26T02:20:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-27T01:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-17T10:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-27T10:50:00.000-04:00" comment="modified wft-564 - Changed test to match comment">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-06-23T12:49:00.000-04:00" comment="modified obj:490 - Chagned the pattern match operation to equals since there was no need for a regular expression.">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-06-23T11:35:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:31.382-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:45:58.311-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:47.041-05:00">ACCEPTED</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.853-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-10-25T16:53:30.233-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:01:19.716-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:54.318-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:23.836-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1476" negate="false" test_ref="oval:org.mitre.oval:tst:856"/>
          <criterion comment="the patch kb834707 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:855"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Users not saving encrypted pages to disk  (DisableCachingOfSSLPages)" negate="false" test_ref="oval:org.mitre.oval:tst:588"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5725" version="3" class="vulnerability">
      <metadata>
        <title>DNS Insufficient Socket Entropy Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1447" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1447"/>
        <description>The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2; and other implementations allow remote attackers to spoof DNS traffic via a birthday attack that uses in-bailiwick referrals to conduct cache poisoning against recursive resolvers, related to insufficient randomness of DNS transaction IDs and source ports, aka "DNS Insufficient Socket Entropy Vulnerability" or "the Kaminsky bug."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-08T14:18:00">
              <contributor organization="Secure Elements, Inc.">Jeff Ito</contributor>
            </submitted>
            <status_change date="2008-07-11T10:55:58.695-04:00">DRAFT</status_change>
            <status_change date="2008-07-28T04:00:23.732-04:00">INTERIM</status_change>
            <status_change date="2008-08-18T04:00:52.726-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8348 - Updated def:5725 to support DNS client too. Updated def:5380 to add LDR version check." date="2011-10-28T20:15:00.076-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2011-10-28T20:23:10.881-04:00">INTERIM</status_change>
            <status_change date="2011-11-14T04:00:45.190-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win 2K SP4 and vulnerable version of file">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criteria operator="OR" comment="Check for vulnerable version of server or client file">
            <criterion comment="dnsapi.dll version is less than 5.0.2195.7280" test_ref="oval:org.mitre.oval:tst:8348"/>
            <criterion comment="Dns.exe version is less than 5.0.2195.7162" test_ref="oval:org.mitre.oval:tst:8430"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win XP SP2 X86 and vulnerable version of client file">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="dnsapi.dll version is less than 5.1.2600.3394" test_ref="oval:org.mitre.oval:tst:8137"/>
        </criteria>
        <criteria operator="AND" comment="Win XP SP3 X86 and vulnerable version of client file">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="dnsapi.dll version is less than 5.1.2600.5625" test_ref="oval:org.mitre.oval:tst:8530"/>
        </criteria>
        <criteria operator="AND" comment="Win XP X64 SP1 and vulnerable version of client file">
          <extend_definition comment="Microsoft Windows XP Professional x64 Edition SP1 is installed" definition_ref="oval:org.mitre.oval:def:720"/>
          <criterion comment="dnsapi.dll version is less than 5.2.3790.3161" test_ref="oval:org.mitre.oval:tst:8185"/>
        </criteria>
        <criteria operator="AND" comment="Win XP X64 and vulnerable version of client file">
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          <criterion comment="dnsapi.dll version is less than 5.2.3790.4318" test_ref="oval:org.mitre.oval:tst:8047"/>
        </criteria>
        <criteria operator="AND" comment="Win 2k3 SP1 and vulnerable version of client or server file">
          <criteria operator="OR" comment="Win 2K3 SP1 (X86/ X64/IA64)">
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version of client or server file">
            <criterion comment="dnsapi.dll version is less than 5.2.3790.3161" test_ref="oval:org.mitre.oval:tst:8185"/>
            <criterion comment="dns.exe version is less than 5.2.3790.3161" test_ref="oval:org.mitre.oval:tst:8599"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 2k3 SP2 and vulnerable version of client or server file">
          <criteria operator="OR" comment="Win 2K3 SP2 (X86/ X64/IA64)">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version of client or server file">
            <criterion comment="dnsapi.dll version is less than 5.2.3790.4318" test_ref="oval:org.mitre.oval:tst:8047"/>
            <criterion comment="dns.exe version is less than 5.2.3790.4318" test_ref="oval:org.mitre.oval:tst:8535"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5723" version="5" class="vulnerability">
      <metadata>
        <title>Uninitialized Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0554" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0554"/>
        <description>Microsoft Internet Explorer 5.01 SP4, 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on Windows Server 2003 SP1 and SP2, 7 on Windows Vista Gold and SP1, and 7 on Windows Server 2008 allows remote attackers to execute arbitrary code via a web page that triggers presence of an object in memory that was (1) not properly initialized or (2) deleted, aka "Uninitialized Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-04-14T16:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-04-17T16:45:26.673-04:00">DRAFT</status_change>
            <status_change date="2009-05-04T04:00:15.073-04:00">INTERIM</status_change>
            <status_change date="2009-05-25T04:01:43.561-04:00">ACCEPTED</status_change>
            <modified comment="Removed CVE from title. Removed Microsoft reference" date="2009-06-01T16:05:28.035-04:00">
              <contributor organization="The MITRE Corporation">Brendan Miles</contributor>
            </modified>
            <status_change date="2009-06-08T04:00:45.517-04:00">INTERIM</status_change>
            <status_change date="2009-06-29T04:00:33.790-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5723 - extended definitions of OS are without SP checks" date="2014-07-28T17:39:00.892-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:41:16.779-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:02.222-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE5/Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="Mshtml.dll version is less than 5.0.3874.1900" test_ref="oval:org.mitre.oval:tst:9783"/>
        </criteria>
        <criteria operator="AND" comment="IE6/Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1625" test_ref="oval:org.mitre.oval:tst:9684"/>
        </criteria>
        <criteria operator="AND" comment="IE6/XP">
          <extend_definition comment="Microsoft Windows XP is installed" definition_ref="oval:org.mitre.oval:def:105"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3527" test_ref="oval:org.mitre.oval:tst:9744"/>
        </criteria>
        <criteria operator="AND" comment="IE6/XP(32-bit)">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5764" test_ref="oval:org.mitre.oval:tst:9622"/>
        </criteria>
        <criteria operator="AND" comment="IE6/Server 2003(32-bit)">
          <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.3304" test_ref="oval:org.mitre.oval:tst:9395"/>
        </criteria>
        <criteria operator="AND" comment="IE6/Server 2003(32-bit)">
          <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4470" test_ref="oval:org.mitre.oval:tst:9788"/>
        </criteria>
        <criteria operator="AND" comment="IE6/XP x64/Server 2003 x64">
          <criteria operator="OR" comment="XP x64/Server 2003 x64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.3304" test_ref="oval:org.mitre.oval:tst:9395"/>
        </criteria>
        <criteria operator="AND" comment="IE6/XP x64/Server 2003 x64">
          <criteria operator="OR" comment="XP x64/Server 2003 x64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4470" test_ref="oval:org.mitre.oval:tst:9788"/>
        </criteria>
        <criteria operator="AND" comment="IE6/XP x64/Server 2003 (ia64)">
          <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.3304" test_ref="oval:org.mitre.oval:tst:9395"/>
        </criteria>
        <criteria operator="AND" comment="IE6/XP x64/Server 2003 (ia64)">
          <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4470" test_ref="oval:org.mitre.oval:tst:9788"/>
        </criteria>
        <criteria operator="AND" comment="IE7/XP x86/x64">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16825" test_ref="oval:org.mitre.oval:tst:9976"/>
        </criteria>
        <criteria operator="AND" comment="IE7/XP x86/x64">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21015" test_ref="oval:org.mitre.oval:tst:9705"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16825" test_ref="oval:org.mitre.oval:tst:9976"/>
        </criteria>
        <criteria operator="AND" comment="IE7/Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21015" test_ref="oval:org.mitre.oval:tst:9705"/>
        </criteria>
        <criteria operator="AND" comment="Mshtml.dll/Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9392"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.16830" test_ref="oval:org.mitre.oval:tst:9688"/>
        </criteria>
        <criteria operator="AND" comment="Mshtml.dll/Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6000.21023" test_ref="oval:org.mitre.oval:tst:10115"/>
        </criteria>
        <criteria operator="AND" comment="Mshtml.dll/Vista x86/x64/Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64/Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.16000" test_ref="oval:org.mitre.oval:tst:9444"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.18226" test_ref="oval:org.mitre.oval:tst:10150"/>
        </criteria>
        <criteria operator="AND" comment="Mshtml.dll/Vista x86/x64/Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64/Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
          <criterion comment="Mshtml.dll version is less than 7.0.6001.22389" test_ref="oval:org.mitre.oval:tst:10005"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5720" version="5" class="vulnerability">
      <metadata>
        <title>HTML Objects Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1442" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1442"/>
        <description>Heap-based buffer overflow in the substringData method in Microsoft Internet Explorer 6 and 7 allows remote attackers to execute arbitrary code, related to an unspecified manipulation of a DOM object before a call to this method, aka the "HTML Objects Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-06-10T14:50:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-06-12T13:58:49.284-04:00">DRAFT</status_change>
            <status_change date="2008-06-30T04:00:18.670-04:00">INTERIM</status_change>
            <status_change date="2008-07-21T04:00:19.533-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5720 - Added LDR support" date="2011-10-25T14:12:00.742-04:00">
              <contributor organization="SecPod Technologies">Pooja Shetty</contributor>
            </modified>
            <status_change date="2011-10-25T14:18:08.519-04:00">INTERIM</status_change>
            <status_change date="2011-11-14T04:00:44.405-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5720 - extended definitions of OS are without SP checks" date="2014-07-28T17:39:00.892-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:41:17.676-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:01.956-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win 2K + IE6">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1611" test_ref="oval:org.mitre.oval:tst:8059"/>
        </criteria>
        <criteria operator="AND" comment="Win XP X86 and IE 6">
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3354" test_ref="oval:org.mitre.oval:tst:8055"/>
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
        </criteria>
        <criteria operator="AND" comment="Win XP / Win 2K3">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="Win XP / Win 2K3">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR / GDR">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16674" test_ref="oval:org.mitre.oval:tst:7361"/>
            <criteria operator="AND" comment="Check for GDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.20815" test_ref="oval:org.mitre.oval:tst:44283"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win XP X64 /Win 2K3 and IE6">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.3123" test_ref="oval:org.mitre.oval:tst:7949"/>
          <criteria operator="OR" comment="Win XP X64 /Win 2K3">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win XP X64/ Win 2K3 and IE 6">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4275" test_ref="oval:org.mitre.oval:tst:7988"/>
          <criteria operator="OR" comment="Win XP X64 /Win 2K3">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win Vista and IE 7">
          <extend_definition comment="Microsoft Windows Vista is installed" definition_ref="oval:org.mitre.oval:def:228"/>
          <criteria operator="OR" comment="Check for LDR / GDR">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16681" test_ref="oval:org.mitre.oval:tst:8012"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.20823" test_ref="oval:org.mitre.oval:tst:44003"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
        </criteria>
        <criteria operator="AND" comment="Win Vista / Win 2K8 and IE 7">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="Win Vista / Win 2K8">
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR / GDR">
            <criterion comment="Mshtml.dll version is less than 7.0.6001.18063" test_ref="oval:org.mitre.oval:tst:8066"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Mshtml.dll version is greater than or equal to 7.0.6001.22000" test_ref="oval:org.mitre.oval:tst:42152"/>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6001.22167" test_ref="oval:org.mitre.oval:tst:43645"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win XP X86 + IE6">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.2900.5583" test_ref="oval:org.mitre.oval:tst:43822"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5716" version="8" class="vulnerability">
      <metadata>
        <title>Microsoft .NET Framework Pointer Verification Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft .NET Framework</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0090" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0090"/>
        <description>Microsoft .NET Framework 1.0 SP3, 1.1 SP1, and 2.0 SP1 does not properly validate .NET verifiable code, which allows remote attackers to obtain unintended access to stack memory, and execute arbitrary code, via (1) a crafted XAML browser application (XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Microsoft .NET Framework Pointer Verification Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-13T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-10-22T17:36:55.227-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:21.996-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:07.631-05:00">ACCEPTED</status_change>
            <modified comment="Updated to reference obj:2009" date="2009-12-01T17:59:00.669-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2009-12-01T18:00:44.235-05:00">INTERIM</status_change>
            <modified comment="Updated to reference obj:2009" date="2009-12-01T18:00:00.766-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <modified comment="Updated to reference obj:2009" date="2009-12-01T18:01:00.229-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <modified comment="Updated to reference obj:2009" date="2009-12-01T18:01:00.547-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2009-12-21T04:00:37.997-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5716 - Updated defs for MS09-061 - updated criteria and modified the GDR/LDR format." date="2011-01-31T17:30:00.645-05:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-01-31T17:33:02.153-05:00">INTERIM</status_change>
            <status_change date="2011-02-21T04:00:52.645-05:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:47.368-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:47.368-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:05.847-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5716 - extended definitions of OS are without SP checks" date="2014-07-28T17:39:00.892-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:41:18.399-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:01.746-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment=".NET Framework 1.1 SP1">
          <criteria operator="OR" comment="OS section">
            <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 1.1 Service Pack 1 is Installed" definition_ref="oval:org.mitre.oval:def:1834"/>
          <criterion comment="the version of Mscorlib.dll is less than 1.1.4322.2443" test_ref="oval:org.mitre.oval:tst:10854"/>
        </criteria>
        <criteria operator="AND" comment=".NET Framework 2.0 SP1">
          <criteria operator="OR" comment="OS section">
            <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:6428"/>
          <criterion comment="the version of Mscorlib.dll is less than 2.0.50727.1873" test_ref="oval:org.mitre.oval:tst:10790"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6428" version="7" class="inventory">
      <metadata>
        <title>Microsoft .NET Framework 2.0 Service Pack 1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft .NET Framework 2.0</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:.net_framework:2.0:sp1"/>
        <description>Microsoft .NET Framework 2.0 Service Pack 1 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-13T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-10-22T17:36:54.776-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:58.304-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:42.417-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:10609 - Created OVAL vulnerability definition for MS10-070" date="2011-02-28T09:25:00.601-05:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-02-28T09:32:47.656-05:00">INTERIM</status_change>
            <status_change date="2011-03-21T04:00:15.336-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:10609 - Corrected object references for def:6428" date="2011-04-19T14:59:00.168-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-04-19T15:00:56.735-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:39.281-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6428 - .NET Framework inventories with modified products." date="2014-03-18T14:31:00.962-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-18T14:33:24.047-04:00">INTERIM</status_change>
            <status_change date="2014-04-07T04:06:56.139-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="The version of Mscorlib.dll is greater than or equal to 2.0.50727.1433" test_ref="oval:org.mitre.oval:tst:10609"/>
        <criterion comment="The version of Mscorlib.dll is less than 2.0.50727.3053" test_ref="oval:org.mitre.oval:tst:10967"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5715" version="3" class="vulnerability">
      <metadata>
        <title>DNS Server Response Validation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0234" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0234"/>
        <description>The DNS Resolver Cache Service (aka DNSCache) in Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008 does not properly cache crafted DNS responses, which makes it easier for remote attackers to predict transaction IDs and poison caches by sending many crafted DNS queries that trigger "unnecessary lookups," aka "DNS Server Response Validation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-03-10T16:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-03-13T20:24:01.232-04:00">DRAFT</status_change>
            <status_change date="2009-03-30T04:00:19.342-04:00">INTERIM</status_change>
            <status_change date="2009-04-20T04:00:16.984-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5715 - - &quot;def:5715 updated to included missing LDR support.&quot; - &quot;def:6138 updated by removing non-vuln Win2008 criteria.&quot; - &quot;def:6117 updated do merged all common criteria.&quot;. - &quot;def:6228 updated to included missing LDR support.&quot;" date="2011-10-27T09:52:00.232-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2011-10-27T10:01:16.986-04:00">INTERIM</status_change>
            <status_change date="2011-11-14T04:00:43.855-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Microsoft Windows Server 2000 SP4 is installed and version of dns.exe">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of dns.exe is less than 5.0.2195.7260" test_ref="oval:org.mitre.oval:tst:9653"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Windows Server 2003 SP1 (x86/x64/ia64) is installed and file version of dns.exe">
          <criteria operator="OR" comment="Microsoft Windows Server 2003 SP1 (x86/x64/ia64) is installed">
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:4386"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
          </criteria>
          <criterion comment="the version of dns.exe is less than 5.2.3790.3295" test_ref="oval:org.mitre.oval:tst:9777"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Windows Server 2003 SP2 (x86/x64/ia64) is installed and file versions of dns.exe">
          <criteria operator="OR" comment="Microsoft Windows Server 2003 SP2 (x86/x64/ia64) is installed">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of dns.exe is less than 5.2.3790.4460" test_ref="oval:org.mitre.oval:tst:9346"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Windows Server 2008 (x86/x64) is installed and file version of dns.exe">
          <criteria operator="OR" comment="Microsoft Windows Server 2008 (x86/x64) is installed">
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criteria operator="OR" comment="version of dns.exe less than 6.0.6001.18214 or greater than or equal 6.0.6001.22000 and less than 6.0.6001.22375">
            <criterion comment="the version of dns.exe is less than 6.0.6001.18214" test_ref="oval:org.mitre.oval:tst:9751"/>
            <criteria operator="AND" comment="For LDR file version greater than or equal 6.0.6001.22000 and less than 6.0.6001.22375">
              <criterion comment="the version of dns.exe is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:44438"/>
              <criterion comment="the version of dns.exe is less than 6.0.6001.22375" test_ref="oval:org.mitre.oval:tst:44142"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5706" version="5" class="vulnerability">
      <metadata>
        <title>HTML Objects Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Internet Explorer 7</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4259" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4259"/>
        <description>Microsoft Internet Explorer 7 sometimes attempts to access uninitialized memory locations, which allows remote attackers to execute arbitrary code via a crafted HTML document that triggers memory corruption, related to a WebDAV request for a file with a long name, aka "HTML Objects Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-12-09T13:31:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-12-12T16:42:50.201-05:00">DRAFT</status_change>
            <status_change date="2008-12-29T04:00:22.147-05:00">INTERIM</status_change>
            <status_change date="2009-01-19T04:00:09.319-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5706 - Submission from SecPod" date="2011-11-14T13:25:00.552-05:00">
              <contributor organization="SecPod Technologies">Pradeep R B</contributor>
            </modified>
            <status_change date="2011-11-14T13:28:28.555-05:00">INTERIM</status_change>
            <status_change date="2011-12-05T04:00:29.308-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5706 - extended definitions of OS are without SP checks" date="2014-07-28T17:39:00.892-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:41:18.845-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:00.933-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
        <criteria operator="OR" comment="Vulnerable IE 7">
          <criteria operator="AND" comment="Check for Vulnerable XP(x86)/(x64)/2003 (ia-64) and Mshtml.dll version">
            <criteria operator="OR" comment="Check for Vulnerable XP(x86)/(x64)/2003 (ia-64)">
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
              <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            </criteria>
            <criteria operator="OR" comment="Check for LDR/GDR">
              <criteria operator="AND" comment="Check for LDR">
                <criterion comment="Check if version of Mshtml.dll is less than 7.0.6000.20935" test_ref="oval:org.mitre.oval:tst:77411"/>
                <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              </criteria>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.16762" test_ref="oval:org.mitre.oval:tst:9192"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Check for Vulnerable Windows Vista (x86)/(x64) and Mshtml.dll version">
            <criteria operator="OR" comment="Check for Vulnerable Windows Vista (x86)/(x64)">
              <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
              <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            </criteria>
            <criteria operator="OR" comment="Check for LDR\GDR">
              <criterion comment="Mshtml.dll version is less than 7.0.6000.16764" test_ref="oval:org.mitre.oval:tst:9403"/>
              <criteria operator="AND" comment="Check for LDR">
                <criterion comment="Mshtml.dll version is less than 7.0.6000.20937" test_ref="oval:org.mitre.oval:tst:9083"/>
                <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Check for Vulnerable Vista(x86)/(x64)/2008(x86)/(x64) and Mshtml.dll version">
            <criteria operator="OR" comment="Check for Vulnerable Vista(x86)/(x64)/2008(x86)/(x64)">
              <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
              <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
              <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            </criteria>
            <criteria operator="OR" comment="Check for LDR\GDR">
              <criterion comment="Mshtml.dll version is less than 7.0.6001.18157" test_ref="oval:org.mitre.oval:tst:9575"/>
              <criteria operator="AND" comment="Check for LDR">
                <criterion comment="Mshtml.dll version is less than 7.0.6001.22288" test_ref="oval:org.mitre.oval:tst:9182"/>
                <criterion comment="Mshtml.dll version is greater than or equal to 7.0.6001.22000" test_ref="oval:org.mitre.oval:tst:42152"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:57" version="3" class="vulnerability">
      <metadata>
        <title>Improper Cross Domain Security Validation with ShowHelp Functionality</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1328" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1328"/>
        <description>The showHelp() function in Microsoft Internet Explorer 5.01, 5.5, and 6.0 supports certain types of pluggable protocols that allow remote attackers to bypass the cross-domain security model and execute arbitrary code, aka "Improper Cross Domain Security Validation with ShowHelp functionality."</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T05:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Changed IE registry test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:37.203-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:23.759-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the version of mshtml.dll is less than 6.0.2723.2500" negate="false" test_ref="oval:org.mitre.oval:tst:3003"/>
        <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5689" version="8" class="vulnerability">
      <metadata>
        <title>ISATAP Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Windows Media Player 6.4</product>
          <product>Windows Media Server 4.1</product>
          <product>Windows Media Server 9</product>
          <product>Windows Media Format Runtime 7.1</product>
          <product>Windows Media Format Runtime 9.5</product>
          <product>Windows Media Format Runtime 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3010" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3010"/>
        <description>Microsoft Windows Media Player 6.4, Windows Media Format Runtime 7.1 through 11, and Windows Media Services 4.1 and 9 incorrectly associate ISATAP addresses with the Local Intranet zone, which allows remote servers to capture NTLM credentials, and execute arbitrary code through credential-reflection attacks, by sending an authentication request, aka "ISATAP Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-12-10T10:44:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-12-12T16:42:50.648-05:00">DRAFT</status_change>
            <status_change date="2008-12-29T04:00:20.483-05:00">INTERIM</status_change>
            <status_change date="2009-01-19T04:00:08.174-05:00">ACCEPTED</status_change>
            <modified comment="Including checks for Windows Media Player 6.4" date="2009-12-01T17:33:00.624-05:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2009-12-01T17:34:00.631-05:00">INTERIM</status_change>
            <status_change date="2009-12-21T04:00:36.869-05:00">ACCEPTED</status_change>
            <modified comment="corrected file name from Nscm.exe to Nsum.exe for obj:6532" date="2010-04-16T14:46:00.908-04:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2010-04-16T14:50:18.869-04:00">INTERIM</status_change>
            <status_change date="2010-05-17T04:00:06.384-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5689 - def:5942 &amp; def:5689, Enhanced to cover WinVista, 2008, 2003 &amp; also 64-bit with service packs" date="2011-11-15T14:56:00.873-05:00">
              <contributor organization="SecPod Technologies">Pradeep R B</contributor>
            </modified>
            <status_change date="2011-11-15T14:58:47.799-05:00">INTERIM</status_change>
            <status_change date="2011-12-05T04:00:28.332-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5689 - extended definitions of OS are without SP checks" date="2014-07-28T17:39:00.892-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:41:14.781-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:00.524-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for Media player 6.4">
          <extend_definition comment="Windows Media Player 6.4 is installed." definition_ref="oval:org.mitre.oval:def:6408"/>
          <criteria operator="OR" comment="Check for Windows 2000/XP/2003">
            <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
          </criteria>
          <criterion comment="the version of Strmdll.dll is less than 4.1.0.3937" test_ref="oval:org.mitre.oval:tst:11104"/>
          <criteria operator="OR" comment="Check for Windows XP/2003">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <criterion comment="the version of Wstrmdll.dll is less than 4.1.0.3937" test_ref="oval:org.mitre.oval:tst:11180"/>
        </criteria>
        <criteria operator="AND" comment="Check for Windows 2000,Media Services 4.1 and Nsum.exe version">
          <extend_definition comment="Microsoft Media Services 4.1 is installed" definition_ref="oval:org.mitre.oval:def:5705"/>
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <criterion comment="Nsum.exe version is less than 4.1.0.3936" test_ref="oval:org.mitre.oval:tst:9602"/>
        </criteria>
        <criteria operator="AND" comment="Check for Media Services 9">
          <extend_definition comment="Microsoft Media Services 9 is installed" definition_ref="oval:org.mitre.oval:def:5844"/>
          <criteria operator="OR" comment="Check for vulnerable Media Services 9 and Wmsserver.dll version">
            <criteria operator="AND" comment="Check for Windows 2003">
              <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
              <criterion comment="Wmsserver.dll version is less than 9.1.1.3845" test_ref="oval:org.mitre.oval:tst:9156"/>
            </criteria>
            <criteria operator="AND" comment="Check for Windows 2003">
              <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
              <criterion comment="Wmsserver.dll version is less than 9.1.1.5000" test_ref="oval:org.mitre.oval:tst:9492"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for Media Player 7.1,Windows 2000 and Wmstream.dll version">
          <extend_definition comment="Windows Media Player v7.1 is installed." definition_ref="oval:org.mitre.oval:def:1386"/>
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <criterion comment="Wmstream.dll version is less than 7.10.0.3082" test_ref="oval:org.mitre.oval:tst:8658"/>
        </criteria>
        <criteria operator="AND" comment="Check for Media Player 9">
          <extend_definition comment="Windows Media Player v9 is installed." definition_ref="oval:org.mitre.oval:def:2147"/>
          <criteria operator="OR" comment="Check for vulnerable Media Player 9">
            <criteria operator="AND" comment="Check for Windows 2000/XP and Wmnetmgr.dll version">
              <criterion comment="Wmnetmgr.dll version is less than 9.0.0.3268" test_ref="oval:org.mitre.oval:tst:9440"/>
              <criteria operator="OR" comment="Check for Windows 2000/XP">
                <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
                <extend_definition comment="Microsoft Windows XP is installed" definition_ref="oval:org.mitre.oval:def:105"/>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Check for Windows XP and Wmnetmgr.dll version">
              <criterion comment="Wmnetmgr.dll version is less than 9.0.0.4504" test_ref="oval:org.mitre.oval:tst:9564"/>
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for Media Player v10">
          <extend_definition comment="Windows Media Player v10 is installed." definition_ref="oval:org.mitre.oval:def:2172"/>
          <criteria operator="OR" comment="Check for vulnerable Media Player 10">
            <criteria operator="AND" comment="Check for Windows XP and Wmnetmgr.dll version">
              <criterion comment="Wmnetmgr.dll version is less than 10.0.0.3703" test_ref="oval:org.mitre.oval:tst:9104"/>
              <criteria operator="OR" comment="Check for Windows XP">
                <extend_definition comment="Microsoft Windows XP is installed" definition_ref="oval:org.mitre.oval:def:105"/>
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Check for Windows 2003 and Wmnetmgr.dll version">
              <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
              <criterion comment="Wmnetmgr.dll version is less than 10.0.0.3711" test_ref="oval:org.mitre.oval:tst:9257"/>
            </criteria>
            <criteria operator="AND" comment="Check for Windows 2003 and Wmnetmgr.dll version">
              <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
              <criterion comment="Wmnetmgr.dll version is less than 10.0.0.4001" test_ref="oval:org.mitre.oval:tst:9445"/>
            </criteria>
            <criteria operator="AND" comment="Check for Windows XP/2003 and Wmnetmgr.dll version">
              <criteria operator="OR" comment="Check for Windows XP/2003">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Wmnetmgr.dll version is less than 10.0.0.3711" test_ref="oval:org.mitre.oval:tst:9257"/>
            </criteria>
            <criteria operator="AND" comment="Check for Windows XP/2003(x64) and Wmnetmgr.dll version">
              <criteria operator="OR" comment="Check for Windows XP/2003(x64)">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Wmnetmgr.dll version is less than 10.0.0.4001" test_ref="oval:org.mitre.oval:tst:9445"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for Media Player v11">
          <extend_definition comment="Windows Media Player v11 is installed." definition_ref="oval:org.mitre.oval:def:2126"/>
          <criteria operator="OR" comment="Check for vulnerable Media Player 10">
            <criteria operator="AND" comment="Check for Windows XP(32)/(64) and Wmnetmgr.dll version">
              <criterion comment="Wmnetmgr.dll version is less than 11.0.5721.5251" test_ref="oval:org.mitre.oval:tst:9534"/>
              <criteria operator="OR" comment="Check for Windows XP(32)/(64)">
                <extend_definition comment="Microsoft Windows XP is installed" definition_ref="oval:org.mitre.oval:def:105"/>
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Check for Windows Vista and Wmnetmgr.dll version">
              <criterion comment="Check if version of Wmnetmgr.dll is less than 11.0.6000.6346" test_ref="oval:org.mitre.oval:tst:77438"/>
              <criteria operator="OR" comment="Check for Windows Vista">
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Check for Windows Vista/2008 and Wmnetmgr.dll version">
              <criterion comment="Check if version of Wmnetmgr.dll is less than 11.0.6001.7001" test_ref="oval:org.mitre.oval:tst:77313"/>
              <criteria operator="OR" comment="Check for Windows Vista/2008">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6408" version="7" class="inventory">
      <metadata>
        <title>Windows Media Player 6.4 is installed.</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows Media Player 6.4</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:windows_media_player:6.4"/>
        <description>Windows Media Player 6.4 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-13T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-10-22T17:37:00.599-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:53.822-05:00">INTERIM</status_change>
            <status_change date="2009-12-07T04:00:58.800-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:2581 - On definition oval:org.mitre.oval:def:7384  I changed the affected platform from &quot;Microsoft Windows 2008&quot; to &quot;Microsoft Windows Server 2008&quot;" date="2011-05-12T10:52:00.860-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2011-05-12T10:58:12.388-04:00">INTERIM</status_change>
            <status_change date="2011-05-30T04:00:53.383-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6408 - Modifications vary from minor OVAL title/description changes to suggesting an alternative CPE name to use." date="2011-09-28T11:29:00.976-04:00">
              <contributor organization="The MITRE Corporation">David Rothenberg</contributor>
            </modified>
            <status_change date="2011-09-28T11:33:34.477-04:00">INTERIM</status_change>
            <status_change date="2011-10-17T04:00:23.012-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6408 - Modified Win Media Player inventories: Fixed product version info" date="2015-04-10T10:03:00.585-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-04-10T10:05:27.041-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:27.812-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Windows Media Player 6.4 is installed" test_ref="oval:org.mitre.oval:tst:10296"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5844" version="3" class="inventory">
      <metadata>
        <title>Microsoft Media Services 9 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Media Services 9</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:windows_media_services:9"/>
        <description>The application Microsoft Media Services 9 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-12-10T10:00:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-12-12T16:42:38.951-05:00">DRAFT</status_change>
            <status_change date="2008-12-29T04:00:28.392-05:00">INTERIM</status_change>
            <status_change date="2009-01-19T04:00:12.096-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5844 - Modifications vary from minor OVAL title/description changes to suggesting an alternative CPE name to use." date="2011-09-28T11:29:00.976-04:00">
              <contributor organization="The MITRE Corporation">David Rothenberg</contributor>
            </modified>
            <status_change date="2011-09-28T11:33:15.798-04:00">INTERIM</status_change>
            <status_change date="2011-10-17T04:00:21.461-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media\Server!Version exists and is ~ 9" test_ref="oval:org.mitre.oval:tst:9330"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5705" version="3" class="inventory">
      <metadata>
        <title>Microsoft Media Services 4.1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Media Services 4.1</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:windows_media_services:4.1"/>
        <description>The application Microsoft Media Services 4.1 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-12-10T10:00:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-12-12T16:42:38.633-05:00">DRAFT</status_change>
            <status_change date="2008-12-29T04:00:21.824-05:00">INTERIM</status_change>
            <status_change date="2009-01-19T04:00:08.967-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5705 - Modifications vary from minor OVAL title/description changes to suggesting an alternative CPE name to use." date="2011-09-28T11:29:00.976-04:00">
              <contributor organization="The MITRE Corporation">David Rothenberg</contributor>
            </modified>
            <status_change date="2011-09-28T11:33:17.173-04:00">INTERIM</status_change>
            <status_change date="2011-10-17T04:00:21.215-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NetShow!Version exists and is 4.1" test_ref="oval:org.mitre.oval:tst:9193"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5678" version="4" class="vulnerability">
      <metadata>
        <title>Embedded OpenType Font Integer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0232" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0232"/>
        <description>Integer overflow in the Embedded OpenType (EOT) Font Engine in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted name table, aka "Embedded OpenType Font Integer Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-07-14T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-07-20T15:51:26.098-04:00">DRAFT</status_change>
            <status_change date="2009-08-10T04:00:04.260-04:00">INTERIM</status_change>
            <status_change date="2009-08-31T04:00:05.310-04:00">ACCEPTED</status_change>
            <modified comment="Added criteria to test for Windows Vista SP1 and Windows Server 2008 SP1 GDR version. Updated comments for multiple criteria." date="2010-01-19T09:46:00.875-05:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2010-01-19T09:49:42.883-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:04.221-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5678 - Updated several tests to reflect last revision changes from ms09-029." date="2011-10-12T14:31:00.307-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-10-12T14:32:38.735-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:04:10.648-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4 or later">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Fontsub.dll is less than 5.0.2195.7318" test_ref="oval:org.mitre.oval:tst:9808"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="the version of Fontsub.dll is less than 5.1.2600.3607" test_ref="oval:org.mitre.oval:tst:10077"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of Fontsub.dll is less than 5.1.2600.5853" test_ref="oval:org.mitre.oval:tst:9964"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Check for Windows XP (x64) SP2 or Windows 2003">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of Fontsub.dll is less than 5.2.3790.4559" test_ref="oval:org.mitre.oval:tst:10138"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64">
          <criteria operator="OR" comment="Check for Windows Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR check">
            <criterion comment="the version of Fontsub.dll is less than 6.0.6000.16870" test_ref="oval:org.mitre.oval:tst:10238"/>
            <criteria operator="AND" comment="Check for Fontsub.dll LDR version">
              <criterion comment="the version of Fontsub.dll is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:10116"/>
              <criterion comment="the version of Fontsub.dll is less than 6.0.6000.21067" test_ref="oval:org.mitre.oval:tst:10110"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64">
          <criteria operator="OR" comment="Check for Windows Vista SP1 or Windows 2008">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR check">
            <criterion comment="the version of Fontsub.dll is less than 6.0.6001.18272" test_ref="oval:org.mitre.oval:tst:9933"/>
            <criteria operator="AND" comment="Check for Fontsub.dll LDR version">
              <criterion comment="the version of Fontsub.dll is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9819"/>
              <criterion comment="the version of Fontsub.dll is less than 6.0.6001.22450" test_ref="oval:org.mitre.oval:tst:9668"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64">
          <criteria operator="OR" comment="Check for Windows Vista SP2 or Windows 2008 SP2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR check">
            <criterion comment="the version of Fontsub.dll is less than 6.0.6002.18051" test_ref="oval:org.mitre.oval:tst:9958"/>
            <criteria operator="AND" comment="Check for Fontsub.dll LDR version">
              <criterion comment="the version of Fontsub.dll is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10029"/>
              <criterion comment="the version of Fontsub.dll is less than 6.0.6002.22152" test_ref="oval:org.mitre.oval:tst:9813"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5660" version="7" class="vulnerability">
      <metadata>
        <title>Uninitialized Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1919" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1919"/>
        <description>Microsoft Internet Explorer 5.01 SP4 and 6 SP1; Internet Explorer 6 for Windows XP SP2 and SP3 and Server 2003 SP2; and Internet Explorer 7 and 8 for Windows XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 do not properly handle attempts to access deleted objects in memory, which allows remote attackers to execute arbitrary code via an HTML document containing embedded style sheets that modify unspecified rule properties that cause the behavior element to be "improperly processed," aka "Uninitialized Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-07-28T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-08-03T07:48:11.525-04:00">DRAFT</status_change>
            <status_change date="2009-08-24T04:00:05.758-04:00">INTERIM</status_change>
            <status_change date="2009-09-14T04:00:05.183-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5660 - Created new tests to correct the wrong IE8 mshtml.dll file versions for def:5524, def:6072, def:5660." date="2011-01-31T15:35:00.472-05:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-01-31T15:35:52.264-05:00">INTERIM</status_change>
            <status_change date="2011-02-21T04:00:51.706-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:25:01.650-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:10.529-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5660 - extended definitions of OS are without SP checks" date="2014-07-28T17:39:00.892-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:41:17.390-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:06:00.168-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 5.01 on Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="Mshtml.dll version is less than 5.0.3879.2200" test_ref="oval:org.mitre.oval:tst:10309"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1634" test_ref="oval:org.mitre.oval:tst:10442"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on Windows XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3603" test_ref="oval:org.mitre.oval:tst:10058"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on Windows XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5848" test_ref="oval:org.mitre.oval:tst:10127"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on all Windows XP x64, Server 2003 x86,x64,ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4555" test_ref="oval:org.mitre.oval:tst:10273"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows XP x86, x64">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16890" test_ref="oval:org.mitre.oval:tst:9633"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.21089" test_ref="oval:org.mitre.oval:tst:9998"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16890" test_ref="oval:org.mitre.oval:tst:9633"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.21089" test_ref="oval:org.mitre.oval:tst:9998"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16890" test_ref="oval:org.mitre.oval:tst:10074"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.21089" test_ref="oval:org.mitre.oval:tst:10312"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows Vista x86/x64, all Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6001.18294" test_ref="oval:org.mitre.oval:tst:10471"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6001.22475" test_ref="oval:org.mitre.oval:tst:10352"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows Vista x86/x64, Server 2008 x86/64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6002.18071" test_ref="oval:org.mitre.oval:tst:10141"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6002.22180" test_ref="oval:org.mitre.oval:tst:10330"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Windows XP x86/x64, Server 2003 x86/x64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 8.0.6001.18812" test_ref="oval:org.mitre.oval:tst:41916"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
              <criterion comment="Mshtml.dll version is less than 8.0.6001.22902" test_ref="oval:org.mitre.oval:tst:42208"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 8.0.6001.18813" test_ref="oval:org.mitre.oval:tst:42240"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
              <criterion comment="Mshtml.dll version is less than 8.0.6001.22903" test_ref="oval:org.mitre.oval:tst:41308"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5651" version="5" class="vulnerability">
      <metadata>
        <title>Charts Control Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Visual Basic 6.0</product>
          <product>Microsoft Visual FoxPro</product>
          <product>Microsoft Visual Studio .NET 2002</product>
          <product>Microsoft Visual Studio .NET 2003</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4256" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4256"/>
        <description>The Charts ActiveX control in Microsoft Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 does not properly handle errors during access to incorrectly initialized objects, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to corruption of the "system state," aka "Charts Control Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-12-09T13:31:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-12-12T16:42:51.273-05:00">DRAFT</status_change>
            <status_change date="2008-12-29T04:00:18.671-05:00">INTERIM</status_change>
            <status_change date="2009-01-19T04:00:07.574-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5651 - updated by including Visual FoxPro Inventory criteria" date="2011-11-14T13:22:00.233-05:00">
              <contributor organization="SecPod Technologies">Pradeep R B</contributor>
            </modified>
            <status_change date="2011-11-14T13:23:37.274-05:00">INTERIM</status_change>
            <status_change date="2011-12-05T04:00:27.775-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5651 - New inventory definition for VB6, and updates to definitions incorrectly checking VBA inventory instead of VB6." date="2012-10-25T16:38:00.742-04:00">
              <contributor organization="SecPod Technologies">Pradeep R B</contributor>
            </modified>
            <status_change date="2012-10-25T16:58:27.408-04:00">INTERIM</status_change>
            <status_change date="2012-11-12T04:00:32.568-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Visual Studio .NET 2002 SP1 /2003 SP1">
          <criteria operator="OR" comment="Visual Studio .NET 2002 SP1 /2003 SP1">
            <extend_definition comment="Microsoft Visual Studio .NET 2002 SP1 is installed" definition_ref="oval:org.mitre.oval:def:981"/>
            <extend_definition comment="Microsoft Visual Studio .NET 2003 SP1 is installed" definition_ref="oval:org.mitre.oval:def:168"/>
          </criteria>
          <criterion comment="Mschrt20.ocx version is less than 6.1.98.12" test_ref="oval:org.mitre.oval:tst:9283"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Visual Basic 6.0 or VisualFoxPro">
          <criteria operator="OR" comment="Visual Basic 6.0 or VisualFoxPro">
            <extend_definition comment="Microsoft Visual FoxPro is installed" definition_ref="oval:org.mitre.oval:def:14198"/>
            <extend_definition comment="Microsoft Visual Basic 6.0 is installed" definition_ref="oval:org.mitre.oval:def:15369"/>
          </criteria>
          <criterion comment="Mscomct2.ocx version is less than 6.1.98.12" test_ref="oval:org.mitre.oval:tst:9209"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:14198" version="3" class="inventory">
      <metadata>
        <title>Microsoft Visual FoxPro is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Visual FoxPro</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:visual_foxpro"/>
        <description>Microsoft Visual FoxPro is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2011-11-08T12:21:48">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-11-14T13:22:58.537-05:00">DRAFT</status_change>
            <status_change date="2011-12-05T04:00:23.248-05:00">INTERIM</status_change>
            <status_change date="2011-12-26T04:01:18.817-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Microsoft Visual FoxPro is installed" test_ref="oval:org.mitre.oval:tst:77534"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5630" version="4" class="vulnerability">
      <metadata>
        <title>Event System Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1456" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1456"/>
        <description>Array index vulnerability in the Event System in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote authenticated users to execute arbitrary code via a crafted event subscription request that is used to access an array of function pointers.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-13T09:28:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-08-14T15:03:07.486-04:00">DRAFT</status_change>
            <status_change date="2008-09-01T04:01:02.472-04:00">INTERIM</status_change>
            <status_change date="2008-09-22T04:00:27.358-04:00">ACCEPTED</status_change>
            <modified comment="Corrected test comment to reference es.dll instead of Ipsecsvc.dll." date="2009-02-27T15:52:00.695-05:00">
              <contributor organization="Prism Microsystems, Inc.">Maneesh Jolly</contributor>
            </modified>
            <status_change date="2009-02-27T15:55:20.377-05:00">INTERIM</status_change>
            <modified comment="Corrected test comment to reference es.dll instead of Ipsecsvc.dll." date="2009-02-27T15:52:00.237-05:00">
              <contributor organization="Prism Microsystems, Inc.">Maneesh Jolly</contributor>
            </modified>
            <status_change date="2009-03-16T04:00:11.347-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5630 - Added LDR version check &amp; itanium support" date="2011-10-25T14:28:00.689-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2011-10-25T14:31:31.001-04:00">INTERIM</status_change>
            <status_change date="2011-11-14T04:00:41.493-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="win 2000 sp4/version">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of es.dll is less than 2000.2.3550.0" test_ref="oval:org.mitre.oval:tst:9053"/>
        </criteria>
        <criteria operator="AND" comment="win XP SP2/version">
          <criterion comment="the version of es.dll is less than 2001.12.4414.320" test_ref="oval:org.mitre.oval:tst:9013"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
        </criteria>
        <criteria operator="AND" comment="win XP SP3/version">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of es.dll is less than 2001.12.4414.706" test_ref="oval:org.mitre.oval:tst:9019"/>
        </criteria>
        <criteria operator="AND" comment="server 2003 SP1/XP 64 bit/version">
          <criterion comment="the version of es.dll is less than 2001.12.4720.3129" test_ref="oval:org.mitre.oval:tst:9147"/>
          <criteria operator="OR" comment="OS check">
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:4386"/>
            <extend_definition comment="Microsoft Windows XP Professional x64 Edition SP1 is installed" definition_ref="oval:org.mitre.oval:def:720"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="server 2003 SP2/PX SP2 64 bit/version">
          <criterion comment="the version of es.dll is less than 2001.12.4720.4282" test_ref="oval:org.mitre.oval:tst:8200"/>
          <criteria operator="OR" comment="OS check">
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vista/version">
          <extend_definition comment="Microsoft Windows Vista is installed" definition_ref="oval:org.mitre.oval:def:228"/>
          <criteria operator="OR" comment="GDR/LDR">
            <criterion comment="the version of es.dll is less than 2001.12.6930.16677" test_ref="oval:org.mitre.oval:tst:9038"/>
            <criteria operator="AND" comment="LDR range">
              <criterion comment="Check if the version of Es.dll is greater than or equal to 2001.12.6930.20000" test_ref="oval:org.mitre.oval:tst:44426"/>
              <criterion comment="Check if the version of Es.dll is less than 2001.12.6930.20818" test_ref="oval:org.mitre.oval:tst:44006"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="vista sp1/server 2008 sp1/version">
          <criteria operator="OR" comment="OS check">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          </criteria>
          <criteria operator="OR" comment="GDR/LDR">
            <criterion comment="the version of es.dll is less than 2001.12.6931.18057" test_ref="oval:org.mitre.oval:tst:8968"/>
            <criteria operator="AND" comment="LDR range">
              <criterion comment="Check if the version of Es.dll is greater than or equal to 2001.12.6931.22000" test_ref="oval:org.mitre.oval:tst:44378"/>
              <criterion comment="Check if the version of Es.dll is less than 2001.12.6931.22162" test_ref="oval:org.mitre.oval:tst:44340"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5618" version="6" class="vulnerability">
      <metadata>
        <title>MJPEG Decompression Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>DirectX</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0084" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0084"/>
        <description>Use-after-free vulnerability in DirectShow in Microsoft DirectX 8.1 and 9.0 allows remote attackers to execute arbitrary code via an MJPEG file or video stream with a malformed Huffman table, which triggers an exception that frees heap memory that is later accessed, aka "MJPEG Decompression Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-04-14T16:00:00">
              <contributor organization="Gideon Technologies, Inc.">Kyle Key</contributor>
            </submitted>
            <status_change date="2009-04-17T16:45:30.967-04:00">DRAFT</status_change>
            <status_change date="2009-05-04T04:00:13.110-04:00">INTERIM</status_change>
            <status_change date="2009-05-25T04:01:41.728-04:00">ACCEPTED</status_change>
            <modified comment="Removed CVE from title. Removed Microsoft reference" date="2009-06-01T16:05:28.035-04:00">
              <contributor organization="The MITRE Corporation">Brendan Miles</contributor>
            </modified>
            <status_change date="2009-06-08T04:00:42.959-04:00">INTERIM</status_change>
            <status_change date="2009-06-29T04:00:28.038-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:3502 - obj/ste updates to conform to authoring style guide" date="2013-03-26T09:53:00.500-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-03-26T09:55:57.016-04:00">INTERIM</status_change>
            <status_change date="2013-04-15T04:00:26.976-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:9002 - modified comments" date="2014-02-28T15:13:00.247-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-28T15:16:16.005-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:22.261-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="DirectX 8.1 on Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="DirectX 8.1 Installed" test_ref="oval:org.mitre.oval:tst:6805"/>
          <criterion comment="the version of Quartz.dll is less than 6.3.1.892" test_ref="oval:org.mitre.oval:tst:9839"/>
        </criteria>
        <criteria operator="AND" comment="DirectX 9.0 on Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="DirectX 9.0x Installed" test_ref="oval:org.mitre.oval:tst:601"/>
          <criterion comment="the version of Quartz.dll is less than 6.5.1.910" test_ref="oval:org.mitre.oval:tst:9893"/>
        </criteria>
        <criteria operator="AND" comment="DirectX 9.0 on Win XP SP2 x86">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="DirectX 9.0x Installed" test_ref="oval:org.mitre.oval:tst:601"/>
          <criterion comment="the version of Quartz.dll is less than 6.5.2600.3497" test_ref="oval:org.mitre.oval:tst:9952"/>
        </criteria>
        <criteria operator="AND" comment="DirectX 9.0 on Win XP SP3 x86">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="DirectX 9.0x Installed" test_ref="oval:org.mitre.oval:tst:601"/>
          <criterion comment="the version of Quartz.dll is less than 6.5.2600.5731" test_ref="oval:org.mitre.oval:tst:9805"/>
        </criteria>
        <criteria operator="AND" comment="DirectX 9.0 on Windows XP SP1, Server 2003 SP1">
          <criteria operator="OR" comment="2003 sp1 x64\xp sp1 x64\ 2003 sp1 x86\2003 sp1 ia64">
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:4386"/>
            <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
          </criteria>
          <criterion comment="DirectX 9.0x Installed" test_ref="oval:org.mitre.oval:tst:601"/>
          <criterion comment="the version of Quartz.dll is less than 6.5.3790.3266" test_ref="oval:org.mitre.oval:tst:9947"/>
        </criteria>
        <criteria operator="AND" comment="DirectX 9.0 on Windows XP SP2, Server 2003 SP2">
          <criteria operator="OR" comment="xp sp2 x64\2003 sp2 x86\x64\ia64">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="DirectX 9.0x Installed" test_ref="oval:org.mitre.oval:tst:601"/>
          <criterion comment="the version of Quartz.dll is less than 6.5.3790.4431" test_ref="oval:org.mitre.oval:tst:9002"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5602" version="5" class="vulnerability">
      <metadata>
        <title>HTML Objects Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2255" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2255"/>
        <description>Microsoft Internet Explorer 5.01, 6, and 7 accesses uninitialized memory, which allows remote attackers to cause a denial of service (crash) and execute arbitrary code via unknown vectors, a different vulnerability than CVE-2008-2254, aka "HTML Object Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-13T09:28:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-08-14T15:03:08.112-04:00">DRAFT</status_change>
            <status_change date="2008-09-01T04:00:59.756-04:00">INTERIM</status_change>
            <status_change date="2008-09-22T04:00:25.790-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:9018 - Included LDR support &amp; added new state to match correct version." date="2011-10-25T14:07:00.717-04:00">
              <contributor organization="SecPod Technologies">Pooja Shetty</contributor>
            </modified>
            <status_change date="2011-10-25T14:12:09.165-04:00">INTERIM</status_change>
            <status_change date="2011-11-14T04:00:40.120-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5602 - extended definitions of OS are without SP checks" date="2014-07-28T17:39:00.892-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:41:15.051-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:05:59.772-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win 2K + IE6 vulnerable version">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1613" test_ref="oval:org.mitre.oval:tst:8781"/>
        </criteria>
        <criteria operator="AND" comment="Win 2K + IE 5.01">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="Mshtml.dll version is less than 5.0.3866.2000" test_ref="oval:org.mitre.oval:tst:8949"/>
        </criteria>
        <criteria operator="AND" comment="Win XP + IE 6">
          <extend_definition comment="Microsoft Windows XP is installed" definition_ref="oval:org.mitre.oval:def:105"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3395" test_ref="oval:org.mitre.oval:tst:8921"/>
        </criteria>
        <criteria operator="AND" comment="Win XP + IE 6">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5626" test_ref="oval:org.mitre.oval:tst:9128"/>
        </criteria>
        <criteria operator="AND" comment="Win XP /  Win 2K3 + IE 7">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="Win XP / Win 2K3">
            <extend_definition comment="Microsoft Windows XP is installed" definition_ref="oval:org.mitre.oval:def:105"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR / GDR">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16705" test_ref="oval:org.mitre.oval:tst:9018"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Check if the version mshtml.dll is less than 7.0.6000.20861" test_ref="oval:org.mitre.oval:tst:44137"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 2K3 / Win XP X64 and IE 6">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.3167" test_ref="oval:org.mitre.oval:tst:8958"/>
          <criteria operator="OR" comment="Win 2K3 / Win XP X64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win XP X64 / Win 2K3">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4324" test_ref="oval:org.mitre.oval:tst:8988"/>
          <criteria operator="OR" comment="Win 2K3 / Win XP X64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win Vista and IE7">
          <extend_definition comment="Microsoft Windows Vista is installed" definition_ref="oval:org.mitre.oval:def:228"/>
          <criteria operator="OR" comment="Check for LDR and GDR">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16711" test_ref="oval:org.mitre.oval:tst:8163"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.20868" test_ref="oval:org.mitre.oval:tst:44258"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
        </criteria>
        <criteria operator="AND" comment="Win Vista / Win 2K8 and IE7">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="Win Vista/ Win 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR /GDR">
            <criterion comment="Mshtml.dll version is less than 7.0.6001.18099" test_ref="oval:org.mitre.oval:tst:9108"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Mshtml.dll version is greater than or equal to 7.0.6001.22000" test_ref="oval:org.mitre.oval:tst:42152"/>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6001.22212" test_ref="oval:org.mitre.oval:tst:44416"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5592" version="4" class="vulnerability">
      <metadata>
        <title>Windows (ME, NT, 2K), IE v5.5,SP2 CSS Heap Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0842" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0842"/>
        <description>Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from "memory corruption") via certain malformed Cascading Style Sheet (CSS) elements that trigger heap-based buffer overflows, as demonstrated using the "&lt;STYLE>@;/*" string, possibly due to a missing comment terminator that may cause an invalid length to trigger a large memory copy operation, aka the "CSS Heap Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-19T04:49:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-20T02:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:42:00.000-04:00" comment="modified wft-562 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:56.358-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:23.456-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
          <criterion comment="the version of mshtml.dll is less than 5.50.4945.2800" negate="false" test_ref="oval:org.mitre.oval:tst:384"/>
          <criterion comment="the patch kb834707 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:855"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5588" version="6" class="vulnerability">
      <metadata>
        <title>Win32k NULL Pointer Dereferencing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1127" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1127"/>
        <description>win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 does not correctly validate an argument to an unspecified system call, which allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, aka "Win32k NULL Pointer Dereferencing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-10T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-11-12T15:32:29.529-05:00">DRAFT</status_change>
            <status_change date="2009-11-30T04:00:05.811-05:00">INTERIM</status_change>
            <status_change date="2009-12-21T04:00:33.779-05:00">ACCEPTED</status_change>
            <modified comment="Changed operation attribute to 'greater than or equals'" date="2010-02-10T13:05:00.517-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2010-02-10T13:05:54.925-05:00">INTERIM</status_change>
            <modified comment="Changed operation attribute to 'greater than or equals'" date="2010-02-10T13:05:00.923-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2010-03-01T04:00:02.481-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5588 - Modified GDR/LDR service branch format to read easier, removed duplicate, and updated extended def for Vista." date="2011-01-31T13:57:00.353-05:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-01-31T13:59:32.064-05:00">INTERIM</status_change>
            <status_change date="2011-02-21T04:00:50.910-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5160 - contains tests with modified comments and all dependences" date="2014-02-13T12:19:00.287-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:22:58.726-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:09.947-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of win32k.sys is less than 5.0.2195.7322" test_ref="oval:org.mitre.oval:tst:11065"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="the version of win32k.sys is less than 5.1.2600.3614" test_ref="oval:org.mitre.oval:tst:10898"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of win32k.sys is less than 5.1.2600.5863" test_ref="oval:org.mitre.oval:tst:11060"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of win32k.sys is less than 5.2.3790.4571" test_ref="oval:org.mitre.oval:tst:10856"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Vista x86/x64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of win32k.sys is less than 6.0.6000.16908" test_ref="oval:org.mitre.oval:tst:10258"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of win32k.sys is less than 6.0.6000.21108" test_ref="oval:org.mitre.oval:tst:10947"/>
              <criterion comment="the version of win32k.sys is greater than 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9977"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Vista x86/x64 SP1, all Server 2008 x86/x64/ia64">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of win32k.sys is less than 6.0.6001.18311" test_ref="oval:org.mitre.oval:tst:11103"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of win32k.sys is less than 6.0.6001.22497" test_ref="oval:org.mitre.oval:tst:10753"/>
              <criterion comment="the version of win32k.sys is greater than 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:10142"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Vista x86/x64 SP2, Server 2008 x86/64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of win32k.sys is less than 6.0.6002.18091" test_ref="oval:org.mitre.oval:tst:10883"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of win32k.sys is less than 6.0.6002.22200" test_ref="oval:org.mitre.oval:tst:11097"/>
              <criterion comment="the version of win32k.sys is greater than 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10124"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5582" version="3" class="vulnerability">
      <metadata>
        <title>WINS Memory Overwrite Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1451" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1451"/>
        <description>The WINS service on Microsoft Windows 2000 SP4, and Server 2003 SP1 and SP2, does not properly validate data structures in WINS network packets, which allows local users to gain privileges via a crafted packet, aka "Memory Overwrite Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-06-10T16:00:00">
              <contributor organization="Secure Elements, Inc.">Jeff Ito</contributor>
            </submitted>
            <status_change date="2008-06-12T13:58:52.126-04:00">DRAFT</status_change>
            <modified comment="Fixed platforms to include Microsoft Windows Server 2003" date="2008-06-20T15:20:00.356-04:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2008-07-07T04:00:28.941-04:00">INTERIM</status_change>
            <status_change date="2008-07-28T04:00:15.993-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5582 - Included criteria for Win2003 Server Itanium SP1 and SP2, and also added non-root criteria comments." date="2011-10-17T12:46:00.379-04:00">
              <contributor organization="SecPod Technologies">Pradeep R B</contributor>
            </modified>
            <status_change date="2011-10-17T12:47:39.183-04:00">INTERIM</status_change>
            <status_change date="2011-11-07T04:01:01.184-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of wins.exe is less than 5.0.2195.7155" test_ref="oval:org.mitre.oval:tst:7579"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Server 2003 SP1 (x86)/(x64)/(ia-64)">
          <criteria operator="OR" comment="Windows Server 2003 SP1 (x86)/(x64)/(ia-64)">
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
          </criteria>
          <criterion comment="the version of wins.exe is less than 5.2.3790.3119" test_ref="oval:org.mitre.oval:tst:7733"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Server 2003 SP2 (x86)/(x64)/(ia-64)">
          <criteria operator="OR" comment="Windows Server 2003 SP2 (x86)/(x64)/(ia-64)">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 ia64 Service Pack 2 or later is installed" definition_ref="oval:org.mitre.oval:def:1825"/>
          </criteria>
          <criterion comment="the version of wins.exe is less than 5.2.3790.4271" test_ref="oval:org.mitre.oval:tst:7820"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1825" version="12" class="inventory">
      <metadata>
        <title>Microsoft Windows Server 2003 ia64 Service Pack 2 or later is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_server_2003:::itanium"/>
        <description>The operating system installed on the system is Microsoft Windows Server 2003 (ia64) Service Pack 2 or later.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-04-10T16:31:02">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-04-25T19:52:19.986-04:00">INTERIM</status_change>
            <status_change date="2007-05-23T15:05:33.355-04:00">ACCEPTED</status_change>
            <modified comment="Changed the CPE reference" date="2008-04-04T11:17:00.107-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2008-04-04T11:26:07.132-04:00">INTERIM</status_change>
            <status_change date="2008-04-21T04:00:14.343-04:00">ACCEPTED</status_change>
            <modified comment="Multiple corrections and update to POSIX compatibility for ste:2656" date="2010-11-29T16:12:00.873-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-11-29T16:13:01.362-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:36.412-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1825 - Updated Windows 2003 Server CPE names." date="2011-03-29T13:48:00.699-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-03-29T13:51:34.653-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1825 - Updated title and description, and removed CPE reference" date="2011-04-07T11:21:00.437-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-04-25T04:00:19.490-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:44:21.948-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:01:54.362-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1825 - added CPE references in several inventories for uniformity" date="2014-04-10T08:25:00.988-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-04-10T08:32:03.405-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:00:09.874-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Windows Server 2003 is installed" definition_ref="oval:org.mitre.oval:def:128"/>
        <criterion comment="a version of Windows for the ia64 architecture is installed" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" test_ref="oval:org.mitre.oval:tst:2837"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5580" version="3" class="vulnerability">
      <metadata>
        <title>GDI stack Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1087" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1087"/>
        <description>Stack-based buffer overflow in GDI in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, and Server 2008 allows remote attackers to execute arbitrary code via an EMF image file with crafted filename parameters, aka "GDI Stack Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-04-08T16:04:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-04-11T14:11:48.506-04:00">DRAFT</status_change>
            <status_change date="2008-04-28T04:00:24.045-04:00">INTERIM</status_change>
            <status_change date="2008-05-19T04:00:24.061-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5580 - Added LDR critiera &amp; itanium support for Win 2003 &amp; 2008" date="2011-10-25T14:31:00.257-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2011-10-25T14:34:40.877-04:00">INTERIM</status_change>
            <status_change date="2011-11-14T04:00:39.363-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="win 2000/version">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Gdi32.dll version is less than 5.0.2195.7153" test_ref="oval:org.mitre.oval:tst:7313"/>
        </criteria>
        <criteria operator="AND" comment="win XP/version">
          <criterion comment="Gdi32.dll version is less than 5.1.2600.3316" test_ref="oval:org.mitre.oval:tst:7477"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
        </criteria>
        <criteria operator="AND" comment="win XP/server 2003 sp1/version">
          <criterion comment="Gdi32.dll version is less than 5.2.3790.3091" test_ref="oval:org.mitre.oval:tst:7867"/>
          <criteria operator="OR" comment="OS check">
            <extend_definition comment="Microsoft Windows XP Professional x64 Edition SP1 is installed" definition_ref="oval:org.mitre.oval:def:720"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:4386"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="win XP sp2/server 2003 sp2/version">
          <criterion comment="Gdi32.dll version is less than 5.2.3790.4237" test_ref="oval:org.mitre.oval:tst:7979"/>
          <criteria operator="OR" comment="OS check">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="vista/version">
          <criteria operator="OR" comment="OS check">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="GDR/LDR">
            <criterion comment="Gdi32.dll version is less than 6.0.6000.16643" test_ref="oval:org.mitre.oval:tst:7866"/>
            <criteria operator="AND" comment="LDR range">
              <criterion comment="Check if the version of Gdi32.dll is greater than or equal to 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:44319"/>
              <criterion comment="Check if the version of Gdi32.dll is less than 6.0.6000.20777" test_ref="oval:org.mitre.oval:tst:44191"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="vista sp1/server 2008/version">
          <criteria operator="OR" comment="OS check">
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
          </criteria>
          <criteria operator="OR" comment="GDR/LDR">
            <criterion comment="Gdi32.dll version is less than 6.0.6001.18023" test_ref="oval:org.mitre.oval:tst:7782"/>
            <criteria operator="AND" comment="LDR range">
              <criterion comment="Check if the version of Gdi32.dll is greater than or equal to 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:43984"/>
              <criterion comment="Check if the version of Gdi32.dll is less than 6.0.6001.22120" test_ref="oval:org.mitre.oval:tst:44324"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5578" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft Jet Engine MDB File Parsing Stack Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Jet 4.0 Database Engine</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6026" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6026"/>
        <description>Stack-based buffer overflow in Microsoft msjet40.dll 4.0.8618.0 (aka Microsoft Jet Engine), as used by Access 2003 in Microsoft Office 2003 SP3, allows user-assisted attackers to execute arbitrary code via a crafted MDB file database file containing a column structure with a modified column count.  NOTE: this might be the same issue as CVE-2005-0944.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-13T13:39:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-05-15T14:47:41.181-04:00">DRAFT</status_change>
            <status_change date="2008-06-02T04:00:17.211-04:00">INTERIM</status_change>
            <status_change date="2008-06-23T04:00:14.485-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5578 - Modified vulnerabilities - a lot of fixes" date="2015-07-22T13:29:00.390-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-22T13:32:13.693-04:00">INTERIM</status_change>
            <status_change date="2015-08-10T04:00:59.221-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Jet 4.0 Database Engine is installed" definition_ref="oval:org.mitre.oval:def:28307"/>
        <criteria operator="OR">
          <criteria operator="AND" comment="Windows 2000">
            <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
            <criterion comment="Msjet40.dll version is is less than 4.0.9511.0" test_ref="oval:org.mitre.oval:tst:7888"/>
          </criteria>
          <criteria operator="AND" comment="Windows XP">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <criterion comment="Msjet40.dll version is is less than 4.0.9511.0" test_ref="oval:org.mitre.oval:tst:7888"/>
          </criteria>
          <criteria operator="AND" comment="Windows Server 2003">
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <criterion comment="Msjet40.dll version is is less than 4.0.9511.0" test_ref="oval:org.mitre.oval:tst:7888"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28307" version="3" class="inventory">
      <metadata>
        <title>Microsoft Jet 4.0 Database Engine is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Jet 4.0 Database Engine</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:jet:4.0"/>
        <description>Microsoft Jet 4.0 Database Engine is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-05T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </submitted>
            <status_change date="2015-06-10T14:07:24.969-04:00">DRAFT</status_change>
            <status_change date="2015-06-29T04:00:05.307-04:00">INTERIM</status_change>
            <status_change date="2015-07-20T04:00:08.808-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="The file Msjet40.dll exists" test_ref="oval:org.mitre.oval:tst:138848"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5563" version="7" class="vulnerability">
      <metadata>
        <title>Data Stream Handling Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1085" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1085"/>
        <description>Use-after-free vulnerability in Microsoft Internet Explorer 5.01 SP4, 6 through SP1, and 7 allows remote attackers to execute arbitrary code via a crafted data stream that triggers memory corruption, as demonstrated using an invalid MIME-type that does not have a registered handler.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-04-08T16:04:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-04-11T14:11:50.844-04:00">DRAFT</status_change>
            <status_change date="2008-04-28T04:00:23.359-04:00">INTERIM</status_change>
            <status_change date="2008-05-19T04:00:23.023-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5563 - Updated Def:5563 to include missing GDR/QFE versions. Also added comments and included missing extended definitions." date="2011-03-08T13:10:00.760-05:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-03-08T13:11:56.143-05:00">INTERIM</status_change>
            <status_change date="2011-03-28T04:00:10.990-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5563 - def:5563 WinOS SP2 for IE6 was considered as LDR, which is corrected by separating the criteria." date="2011-10-28T20:15:00.796-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2011-10-28T20:20:38.075-04:00">INTERIM</status_change>
            <status_change date="2011-11-14T04:00:38.470-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5563 - extended definitions of OS are without SP checks" date="2014-07-28T17:39:00.892-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:41:14.505-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:05:59.041-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 5.01 on Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="Mshtml.dll version is less than 5.0.3862.1500" test_ref="oval:org.mitre.oval:tst:7890"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1609" test_ref="oval:org.mitre.oval:tst:7575"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on Windows XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3314" test_ref="oval:org.mitre.oval:tst:7791"/>
        </criteria>
        <criteria operator="AND" comment="Intrenet Explorer 6 on Windows XP x64, Server 2003 x86/ia64, Server 2003 x64">
          <criteria operator="OR" comment="Win XP X64 / Win 2K3">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.3091" test_ref="oval:org.mitre.oval:tst:7864"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Windows xp x86/x64, Server 2003 x86/x64/ia64, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Win XP / Win 2K3">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16640" test_ref="oval:org.mitre.oval:tst:7840"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.20772" test_ref="oval:org.mitre.oval:tst:42147"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Windows Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Win Vista 32/ 64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16643" test_ref="oval:org.mitre.oval:tst:7855"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is less than 7.0.6000.20777" test_ref="oval:org.mitre.oval:tst:42312"/>
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Windows Vista x86/x64, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Win Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6001.18023" test_ref="oval:org.mitre.oval:tst:7994"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is less than 7.0.6001.22120" test_ref="oval:org.mitre.oval:tst:42402"/>
              <criterion comment="Mshtml.dll version is greater than or equal to 7.0.6001.22000" test_ref="oval:org.mitre.oval:tst:42152"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win XP X64 / Win 2K3">
          <criteria operator="OR" comment="Win XP X64 or Win 2K3">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4237" test_ref="oval:org.mitre.oval:tst:7992"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5562" version="3" class="vulnerability">
      <metadata>
        <title>SAMI Format Parsing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>DirectX</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1444" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1444"/>
        <description>Stack-based buffer overflow in Microsoft DirectX 7.0 and 8.1 on Windows 2000 SP4 allows remote attackers to execute arbitrary code via a Synchronized Accessible Media Interchange (SAMI) file with crafted parameters for a Class Name variable, aka the "SAMI Format Parsing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-06-10T14:50:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-06-12T13:58:51.684-04:00">DRAFT</status_change>
            <status_change date="2008-06-30T04:00:16.600-04:00">INTERIM</status_change>
            <status_change date="2008-07-21T04:00:16.835-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:3502 - obj/ste updates to conform to authoring style guide" date="2013-03-26T09:53:00.500-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-03-26T09:55:59.296-04:00">INTERIM</status_change>
            <status_change date="2013-04-15T04:00:26.589-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="DirectX 7 on Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="DirectX 7.0x Installed" test_ref="oval:org.mitre.oval:tst:1296"/>
          <criterion comment="the version of Quartz.dll is less than 6.1.9.734" test_ref="oval:org.mitre.oval:tst:7705"/>
        </criteria>
        <criteria operator="AND" comment="DirectX 8.1 on Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="DirectX 8.1 Installed" test_ref="oval:org.mitre.oval:tst:6805"/>
          <criterion comment="the version of Quartz.dll is less than 6.3.1.891" test_ref="oval:org.mitre.oval:tst:7847"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:556" version="4" class="vulnerability">
      <metadata>
        <title>IE v6.0,SP1 Zone Restrictions Bypass via XML Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0817" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0817"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions and read arbitrary files via an XML object.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for specific Windows operating systems.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 sp1 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-01-29T12:00:00.000-04:00" comment="Added Windows XP 64-bit to the list of affected platforms">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:46:02.703-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:45.819-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:50.913-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:23.353-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1276" negate="false" test_ref="oval:org.mitre.oval:tst:2688"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5554" version="1" class="vulnerability">
      <metadata>
        <title>DHTML Object Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1141" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1141"/>
        <description>Microsoft Internet Explorer 6 for Windows XP SP2 and SP3 and Server 2003 SP2 allows remote attackers to execute arbitrary code via unspecified DHTML function calls related to a tr element and the "insertion, deletion and attributes of a table cell," which trigger memory corruption when the window is destroyed, aka "DHTML Object Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-06-09T14:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-06-15T17:06:43.090-04:00">DRAFT</status_change>
            <status_change date="2009-07-06T04:00:22.895-04:00">INTERIM</status_change>
            <status_change date="2009-07-21T07:45:55.326-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3562" test_ref="oval:org.mitre.oval:tst:9989"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5803" test_ref="oval:org.mitre.oval:tst:10078"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4504" test_ref="oval:org.mitre.oval:tst:9507"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5551" version="2" class="vulnerability">
      <metadata>
        <title>Uninitialized Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0552" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0552"/>
        <description>Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4, 6 SP1, 6 on Windows XP SP2 and SP3, and 6 on Windows Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a web page that triggers presence of an object in memory that was (1) not properly initialized or (2) deleted, aka "Uninitialized Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-04-14T16:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-04-17T16:45:32.661-04:00">DRAFT</status_change>
            <status_change date="2009-05-04T04:00:11.281-04:00">INTERIM</status_change>
            <status_change date="2009-05-25T04:01:39.883-04:00">ACCEPTED</status_change>
            <modified comment="Removed CVE from title. Removed Microsoft reference" date="2009-06-01T16:05:28.035-04:00">
              <contributor organization="The MITRE Corporation">Brendan Miles</contributor>
            </modified>
            <status_change date="2009-06-08T04:00:42.233-04:00">INTERIM</status_change>
            <status_change date="2009-06-29T04:00:26.771-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="Mshtml.dll version is less than 5.0.3874.1900" test_ref="oval:org.mitre.oval:tst:9783"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1625" test_ref="oval:org.mitre.oval:tst:9684"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3527" test_ref="oval:org.mitre.oval:tst:9744"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5764" test_ref="oval:org.mitre.oval:tst:9622"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.3304" test_ref="oval:org.mitre.oval:tst:9395"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4470" test_ref="oval:org.mitre.oval:tst:9788"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP1 is installed" definition_ref="oval:org.mitre.oval:def:720"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:4386"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.3304" test_ref="oval:org.mitre.oval:tst:9395"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4470" test_ref="oval:org.mitre.oval:tst:9788"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP1 is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.3304" test_ref="oval:org.mitre.oval:tst:9395"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4470" test_ref="oval:org.mitre.oval:tst:9788"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5531" version="8" class="vulnerability">
      <metadata>
        <title>Windows Media Playback Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Windows Media Format Runtime 9.0</product>
          <product>Windows Media Format Runtime 9.5</product>
          <product>Windows Media Format Runtime 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2499" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2499"/>
        <description>Microsoft Windows Media Format Runtime 9.0, 9.5, and 11; and Microsoft Media Foundation on Windows Vista Gold, SP1, and SP2 and Server 2008; allows remote attackers to execute arbitrary code via an MP3 file with crafted metadata that triggers memory corruption, aka "Windows Media Playback Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-08T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-09-12T20:28:12.381-04:00">DRAFT</status_change>
            <status_change date="2009-09-28T04:00:05.121-04:00">INTERIM</status_change>
            <modified comment="Updated oval:org.mitre.oval:obj:7139 to refer to oval:org.mitre.oval:var:202 rather than the deprecated oval:org.mitre.oval:var:207" date="2009-09-30T20:14:00.930-04:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2009-10-19T04:00:04.430-04:00">ACCEPTED</status_change>
            <modified comment="Corrected comment for var:202 to refer to environment variable" date="2009-12-01T17:28:00.093-05:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2009-12-01T17:32:24.368-05:00">INTERIM</status_change>
            <status_change date="2009-12-21T04:00:32.470-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5531 - def:6257, - Added LDR version check for Windows Media Format 11. - tst:10615 is replaced by new test, as it was pointing to wrong file.  def:5531, - Removed non-vuln Windows Media Services from product tag. - Added LDR version check for Windows Media Format 11. - tst:10615 is replaced by new test, as it was pointing to wrong file." date="2011-10-27T10:12:00.272-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-10-27T10:15:52.870-04:00">INTERIM</status_change>
            <status_change date="2011-11-14T04:00:36.324-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:10337 - modified comments" date="2014-02-28T15:13:00.247-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-28T15:16:22.043-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:21.473-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5531 - extended definitions of OS are without SP checks" date="2014-07-28T17:42:00.658-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:44:53.466-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:05:58.704-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Media Format Runtime 9.0 on Windows 2000 and Windows XP">
          <criteria operator="OR" comment="OS Check">
            <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          </criteria>
          <criterion comment="Wmvcore.dll for Windows Media Format 9.0 is installed." test_ref="oval:org.mitre.oval:tst:125"/>
          <criterion comment="the version of Wmvcore.dll is less than 9.0.0.3270" test_ref="oval:org.mitre.oval:tst:10770"/>
        </criteria>
        <criteria operator="AND" comment="Windows Media Format Runtime 9.0 on Windows XP (x86)">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="Wmvcore.dll for Windows Media Format 9.0 is installed." test_ref="oval:org.mitre.oval:tst:125"/>
          <criterion comment="the version of Wmvcore.dll is less than 9.0.0.4506" test_ref="oval:org.mitre.oval:tst:10757"/>
        </criteria>
        <criteria operator="AND" comment="Windows Media Format Runtime 9.5 on Windows XP (x86)">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="Wmvcore.dll for Windows Media Format 9.5 is installed." test_ref="oval:org.mitre.oval:tst:115"/>
          <criterion comment="the version of Wmvcore.dll is less than 10.0.0.3705" test_ref="oval:org.mitre.oval:tst:10702"/>
        </criteria>
        <criteria operator="AND" comment="Windows Media Format Runtime 11 on Windows XP (x86)">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="Wmvcore.dll for Windows Media Format 11.0 is installed." test_ref="oval:org.mitre.oval:tst:6765"/>
          <criterion comment="the version of Wmvcore.dll is less than 11.0.5721.5265" test_ref="oval:org.mitre.oval:tst:10594"/>
        </criteria>
        <criteria operator="AND" comment="Windows Media Format Runtime 9.5 on Windows XP x64 ans Windows 2003 x64">
          <criteria operator="OR" comment="OS Check">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <criterion comment="Wmvcore.dll for Windows Media Format 9.5 on x64-bit platform is installed." test_ref="oval:org.mitre.oval:tst:10154"/>
          <criterion comment="the version of %SystemRoot%\SysWOW64\Wmvcore.dll is less than 10.0.0.4005" test_ref="oval:org.mitre.oval:tst:10673"/>
        </criteria>
        <criteria operator="AND" comment="Windows Media Format Runtime 11 on Windows XP x64">
          <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          <criterion comment="Wmvcore.dll for Windows Media Format 11.0 on x64-bit platform is installed." test_ref="oval:org.mitre.oval:tst:10083"/>
          <criterion comment="the version of %SystemRoot%\SysWOW64\Wmvcore.dll is less than 11.0.5721.5265" test_ref="oval:org.mitre.oval:tst:10402"/>
        </criteria>
        <criteria operator="AND" comment="Windows Media Format Runtime 9.5 on Windows Server 2003 x86">
          <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
          <criterion comment="Wmvcore.dll for Windows Media Format 9.5 is installed." test_ref="oval:org.mitre.oval:tst:115"/>
          <criterion comment="the version of Wmvcore.dll is less than 10.0.0.4005" test_ref="oval:org.mitre.oval:tst:10704"/>
        </criteria>
        <criteria operator="AND" comment="Windows Media Format Runtime 11 on Windows Vista x86/x64">
          <criteria operator="OR" comment="OS Check">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="Wmvcore.dll for Windows Media Format 11.0 is installed." test_ref="oval:org.mitre.oval:tst:6765"/>
          <criterion comment="the version of Wmvcore.dll is less than 11.0.5721.5265" test_ref="oval:org.mitre.oval:tst:10337"/>
        </criteria>
        <criteria operator="AND" comment="Windows Media Format Runtime 11 on Windows Vista x86/x64, Windows Server 2008 x86/x64">
          <criteria operator="OR" comment="OS Check">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criterion comment="Wmvcore.dll for Windows Media Format 11.0 is installed." test_ref="oval:org.mitre.oval:tst:6765"/>
          <criterion comment="the version of Wmvcore.dll is less than 11.0.6001.7006" test_ref="oval:org.mitre.oval:tst:10211"/>
        </criteria>
        <criteria operator="AND" comment="Windows Media Format Runtime 11 on Windows Vista x86/x64, Windows Server 2008 x86/x64">
          <criteria operator="OR" comment="OS Check">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criterion comment="Wmvcore.dll for Windows Media Format 11.0 is installed." test_ref="oval:org.mitre.oval:tst:6765"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of Wmvcore.dll is less than 11.0.6002.18049" test_ref="oval:org.mitre.oval:tst:44381"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of Wmvcore.dll is greater than or equal 11.0.6002.22000" test_ref="oval:org.mitre.oval:tst:43500"/>
              <criterion comment="the version of Wmvcore.dll is less than 11.0.6002.22150" test_ref="oval:org.mitre.oval:tst:44186"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:553" version="2" class="vulnerability">
      <metadata>
        <title>Microsoft Data Access Components 2.6 Broadcast Response Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Data Access Components 2.6</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0903" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0903"/>
        <description>Buffer overflow in a component of Microsoft Data Access Components (MDAC) 2.5 through 2.8 allows remote attackers to execute arbitrary code via a malformed UDP response to a broadcast request.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.717-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-10-25T16:57:26.904-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:01:19.427-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Microsoft Data Access Components 2.6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2717"/>
        <criterion comment="the version of odbcbcp.dll is less than 2000.80.747.0" negate="false" test_ref="oval:org.mitre.oval:tst:2564"/>
        <criterion comment="the version of sqlsrv32.dll is less than 2000.80.747.0" negate="false" test_ref="oval:org.mitre.oval:tst:2563"/>
        <criterion comment="the patch q832483 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2573"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5524" version="7" class="vulnerability">
      <metadata>
        <title>HTML Objects Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1918" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1918"/>
        <description>Microsoft Internet Explorer 5.01 SP4 and 6 SP1; Internet Explorer 6 for Windows XP SP2 and SP3 and Server 2003 SP2; and Internet Explorer 7 and 8 for Windows XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 do not properly handle table operations, which allows remote attackers to execute arbitrary code via a crafted HTML document that triggers memory corruption by adding malformed elements to an empty DIV element, related to the getElementsByTagName method, aka "HTML Objects Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-07-28T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-08-03T07:48:10.681-04:00">DRAFT</status_change>
            <status_change date="2009-08-24T04:00:03.879-04:00">INTERIM</status_change>
            <status_change date="2009-09-14T04:00:03.777-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5524 - Created new tests to correct the wrong IE8 mshtml.dll file versions for def:5524, def:6072, def:5660." date="2011-01-31T15:35:00.472-05:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-01-31T15:35:55.455-05:00">INTERIM</status_change>
            <status_change date="2011-02-21T04:00:49.882-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4543 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:25:12.597-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:09.674-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5524 - extended definitions of OS are without SP checks" date="2014-07-28T17:37:00.435-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:39:31.015-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:05:58.229-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 5.01 on Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="Mshtml.dll version is less than 5.0.3879.2200" test_ref="oval:org.mitre.oval:tst:10309"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1634" test_ref="oval:org.mitre.oval:tst:10442"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on Windows XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3603" test_ref="oval:org.mitre.oval:tst:10058"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on Windows XP x86">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5848" test_ref="oval:org.mitre.oval:tst:10127"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on all Windows XP x64, Server 2003 x86,x64,ia64">
          <criteria operator="OR" comment="XP x64/server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4555" test_ref="oval:org.mitre.oval:tst:10273"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows XP x86, x64">
          <criteria operator="OR" comment="XP x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16890" test_ref="oval:org.mitre.oval:tst:9633"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.21089" test_ref="oval:org.mitre.oval:tst:9998"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or QFE Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16890" test_ref="oval:org.mitre.oval:tst:9633"/>
            <criteria operator="AND" comment="QFE">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.21089" test_ref="oval:org.mitre.oval:tst:9998"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows Vista x86/x64">
          <criteria operator="OR" comment="Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16890" test_ref="oval:org.mitre.oval:tst:10074"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.21089" test_ref="oval:org.mitre.oval:tst:10312"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows Vista x86/x64, all Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6001.18294" test_ref="oval:org.mitre.oval:tst:10471"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6001.20000" test_ref="oval:org.mitre.oval:tst:9375"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6001.22475" test_ref="oval:org.mitre.oval:tst:10352"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on all Windows Vista x86/x64, Server 2008 x86/64/ia64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/64/ia64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 7.0.6002.18071" test_ref="oval:org.mitre.oval:tst:10141"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10125"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6002.22180" test_ref="oval:org.mitre.oval:tst:10330"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Windows XP x86/x64, Server 2003 x86/x64">
          <criteria operator="OR" comment="XP x86/x64, Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 8.0.6001.18812" test_ref="oval:org.mitre.oval:tst:41916"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
              <criterion comment="Mshtml.dll version is less than 8.0.6001.22902" test_ref="oval:org.mitre.oval:tst:42208"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, Server 2008 x86/x64">
          <criteria operator="OR" comment="Vista x86/x64, Server 2008 x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Mshtml.dll version is less than 8.0.6001.18813" test_ref="oval:org.mitre.oval:tst:42240"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Mshtml.dll version is greater than 8.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9913"/>
              <criterion comment="Mshtml.dll version is less than 8.0.6001.22903" test_ref="oval:org.mitre.oval:tst:41308"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5519" version="7" class="vulnerability">
      <metadata>
        <title>Microsoft Internet Explorer 6 and Internet Explorer 7 KEYGEN element vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3267" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3267"/>
        <description>Microsoft Internet Explorer 6 through 6.0.2900.2180, and 7.0.6000.16711, allows remote attackers to cause a denial of service (CPU consumption) via an automatically submitted form containing a KEYGEN element, a related issue to CVE-2009-1828.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-23T15:11:12">
              <contributor organization="SecPod Technologies">Prabhu.S.A</contributor>
            </submitted>
            <status_change date="2009-09-23T12:25:53.733-04:00">DRAFT</status_change>
            <status_change date="2009-10-12T04:00:04.018-04:00">INTERIM</status_change>
            <status_change date="2009-11-02T04:00:04.392-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5519 - Internet Explorer is installed on the system. was replaced with Microsoft Internet Explorer 7." date="2014-01-14T16:59:00.734-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-14T17:01:03.923-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:45.118-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:41.648-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:23.170-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5358 - modified states" date="2014-02-28T15:16:00.713-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-28T15:17:17.086-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:21.242-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
            <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          </criteria>
          <criteria operator="OR">
            <criteria operator="AND">
              <criterion comment="Check for Internet Explorer less than or equal to 7.0.6000.16711" test_ref="oval:org.mitre.oval:tst:10520"/>
              <criterion comment="Check the Internet Explorer version greater than or equal to 7" test_ref="oval:org.mitre.oval:tst:10737"/>
            </criteria>
            <criteria operator="AND">
              <criterion comment="Check for Internet Explorer less than or equal to 6.0.2900.2180" test_ref="oval:org.mitre.oval:tst:10166"/>
              <criterion comment="Check the Internet Explorer version greater than or equal to 6" test_ref="oval:org.mitre.oval:tst:10382"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:551" version="5" class="vulnerability">
      <metadata>
        <title>MSDTC Unchecked Buffer Permits Remote Code Execution or Privilege Elevation (Win2k,SP4)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>MSDTC</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2119" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2119"/>
        <description>The MIDL_user_allocate function in the Microsoft Distributed Transaction Coordinator (MSDTC) proxy (MSDTCPRX.DLL) allocates a 4K page of memory regardless of the required size, which allows attackers to overwrite arbitrary memory locations using an incorrect size value that is provided to the NdrAllocate function, which writes management data to memory outside of the allocated buffer.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-31T12:00:00.000-04:00" comment="removed an incorrect leading ^ from the value entity of ste:2402">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-31T00:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:49.122-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:44:40.712-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:03:10.701-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="Win2K/XP/2003 service pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2569"/>
        <criteria operator="OR" comment="Either ole32.dll or rpcss.dll has a version less than 5.0.2195.7059">
          <criterion comment="the version of ole32.dll is less than 5.0.2195.7059" negate="false" test_ref="oval:org.mitre.oval:tst:2568"/>
          <criterion comment="the version of rpcss.dll is less than 5.0.2195.7059" negate="false" test_ref="oval:org.mitre.oval:tst:2567"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5495" version="1" class="vulnerability">
      <metadata>
        <title>VBScript and JScript Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0083" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0083"/>
        <description>The (1) VBScript (VBScript.dll) and (2) JScript (JScript.dll) scripting engines 5.1 and 5.6, as used in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2, do not properly decode script, which allows remote attackers to execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-04-08T16:04:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-04-11T14:11:49.070-04:00">DRAFT</status_change>
            <status_change date="2008-04-28T04:00:20.994-04:00">INTERIM</status_change>
            <status_change date="2008-05-19T04:00:21.426-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Jscript.dll version is less than 5.6.0.8835" test_ref="oval:org.mitre.oval:tst:7025"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="Jscript.dll version is less than 5.6.0.8835" test_ref="oval:org.mitre.oval:tst:7025"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP x64 Edition SP1 is installed" definition_ref="oval:org.mitre.oval:def:720"/>
          <criterion comment="Jscript.dll version is less than 5.6.0.8835" test_ref="oval:org.mitre.oval:tst:7025"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          <criterion comment="Jscript.dll version is less than 5.6.0.8835" test_ref="oval:org.mitre.oval:tst:7025"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="Jscript.dll version is less than 5.6.0.8835" test_ref="oval:org.mitre.oval:tst:7025"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <criterion comment="Jscript.dll version is less than 5.6.0.8835" test_ref="oval:org.mitre.oval:tst:7025"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:4386"/>
          <criterion comment="Jscript.dll version is less than 5.6.0.8835" test_ref="oval:org.mitre.oval:tst:7025"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
          <criterion comment="Jscript.dll version is less than 5.6.0.8835" test_ref="oval:org.mitre.oval:tst:7025"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:549" version="3" class="vulnerability">
      <metadata>
        <title>IE v5.5,SP2 Zone Restrictions Bypass via XML Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0817" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0817"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions and read arbitrary files via an XML object.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for specific Windows operating systems.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.5 sp2 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:54.216-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:23.104-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
          <criterion comment="the version of mshtml.dll is less than 5.50.4934.1600" negate="false" test_ref="oval:org.mitre.oval:tst:2689"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5489" version="4" class="vulnerability">
      <metadata>
        <title>Speech API Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0675" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0675"/>
        <description>A certain ActiveX control in sapi.dll (aka the Speech API) in Speech Components in Microsoft Windows Vista, when the Speech Recognition feature is enabled, allows user-assisted remote attackers to delete arbitrary files, and conduct other unauthorized activities, via a web page with an embedded sound object that contains voice commands to an enabled microphone, allowing for interaction with Windows Explorer.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-06-10T14:50:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-06-12T13:58:49.849-04:00">DRAFT</status_change>
            <status_change date="2008-06-30T04:00:15.506-04:00">INTERIM</status_change>
            <status_change date="2008-07-21T04:00:15.025-04:00">ACCEPTED</status_change>
            <modified comment="Added checks for Vista x64, Server 2003 x64/ia64 and Server 2008 x64/ia64" date="2010-01-07T13:26:00.405-05:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2010-01-07T13:27:05.413-05:00">INTERIM</status_change>
            <status_change date="2010-01-25T04:00:03.546-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:3992 - modified vulnerabilities ofÂ MS Visual C++ Â  (winsxs folder checks were modified)" date="2014-04-17T13:09:00.881-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-04-17T13:11:52.991-04:00">INTERIM</status_change>
            <status_change date="2014-05-05T04:00:26.397-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <extend_definition comment="Microsoft Windows XP Professional x64 Edition SP1 is installed" definition_ref="oval:org.mitre.oval:def:720"/>
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:4386"/>
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
          <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP1 is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
          <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
        </criteria>
        <criteria operator="OR">
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{40F23EB7-B397-4285-8F3C-AACE4FA40309}!Compatibility Flags does not exist" test_ref="oval:org.mitre.oval:tst:7937"/>
          <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{40F23EB7-B397-4285-8F3C-AACE4FA40309}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:7734"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5487" version="11" class="vulnerability">
      <metadata>
        <title>HTML Rendering Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference ref_id="CVE-2008-0076" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0076" source="CVE"/>
        <description>Unspecified vulnerability in Microsoft Internet Explorer 5.01, 6 SP1 and SP2, and 7 allows remote attackers to execute arbitrary code via crafted HTML layout combinations, aka "HTML Rendering Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-02-13T10:19:01">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-02-13T16:35:13.635-05:00">DRAFT</status_change>
            <modified date="2008-03-02T04:44:54" comment="Added file check to ensure a full installation.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <modified comment="Fixed typo" date="2008-03-11T09:58:00.328-04:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2008-03-31T04:00:10.487-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5487 - Added LDR support and removed IE 5.01 criteria where appropriate" date="2011-10-25T14:22:00.696-04:00">
              <contributor organization="SecPod Technologies">Pooja Shetty</contributor>
            </modified>
            <status_change date="2011-10-25T14:25:16.419-04:00">INTERIM</status_change>
            <status_change date="2011-11-14T04:00:34.424-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5487 - Correcting incorrect references to 64-bit Itanium XP." date="2012-08-23T17:47:00.168-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-08-23T17:52:03.360-04:00">INTERIM</status_change>
            <status_change date="2012-09-10T04:01:00.001-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:34.682-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:22.953-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5487 - extended definitions of OS are without SP checks" date="2014-07-28T18:04:00.247-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:06:30.604-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5487 - Updated to remove SP checks." date="2014-08-07T14:51:00.976-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-25T04:01:51.551-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 5.01,SP4 on Win2k">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3860.1000" test_ref="oval:org.mitre.oval:tst:7584"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win 2k">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1607" test_ref="oval:org.mitre.oval:tst:7696"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win XP">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2900.3268" test_ref="oval:org.mitre.oval:tst:7834"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win 2003 or Win XP X64">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.3064" test_ref="oval:org.mitre.oval:tst:7573"/>
          <criteria operator="OR" comment="Win XP X64/ Win 2K3">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win 2003 / Win XP X64">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.4210" test_ref="oval:org.mitre.oval:tst:7792"/>
          <criteria operator="OR" comment="Win XP X64 / Win 2K3">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 7 on Win 2003 platforms">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="Win XP / Win 2K3 and IE 7">
            <extend_definition comment="Microsoft Windows XP is installed" definition_ref="oval:org.mitre.oval:def:105"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR / GDR">
            <criterion comment="the version of mshtml.dll is less than 7.0.6000.16608" test_ref="oval:org.mitre.oval:tst:7827"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.20733" test_ref="oval:org.mitre.oval:tst:44297"/>
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 7 on Win Vista platforms">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="Windows Vista 32/ 64 bit">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR / GDR">
            <criterion comment="the version of mshtml.dll is less than 7.0.6000.16609" test_ref="oval:org.mitre.oval:tst:7396"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.20734" test_ref="oval:org.mitre.oval:tst:44122"/>
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5481" version="11" class="vulnerability">
      <metadata>
        <title>ActiveX Object Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference ref_id="CVE-2007-4790" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4790" source="CVE"/>
        <description>Stack-based buffer overflow in certain ActiveX controls in (1) FPOLE.OCX 6.0.8450.0 and (2) Foxtlib.ocx, as used in the Microsoft Visual FoxPro 6.0 fpole 1.0 Type Library; and Internet Explorer 5.01, 6 SP1 and SP2, and 7; allows remote attackers to execute arbitrary code via a long first argument to the FoxDoCmd function.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-02-13T10:19:01">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-02-13T16:35:14.985-05:00">DRAFT</status_change>
            <modified date="2008-03-02T04:44:54" comment="Added file check to ensure a full installation.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <modified comment="Fixed typo" date="2008-03-11T09:58:00.328-04:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2008-03-31T04:00:09.683-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5481 - Added LDR support and removed IE 5.01 criteria where appropriate" date="2011-10-25T14:22:00.696-04:00">
              <contributor organization="SecPod Technologies">Pooja Shetty</contributor>
            </modified>
            <status_change date="2011-10-25T14:25:18.933-04:00">INTERIM</status_change>
            <status_change date="2011-11-14T04:00:33.681-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5481 - Correcting incorrect references to 64-bit Itanium XP." date="2012-08-23T17:47:00.168-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-08-23T17:52:30.625-04:00">INTERIM</status_change>
            <status_change date="2012-09-10T04:00:59.269-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:34.250-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:22.768-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5481 - extended definitions of OS are without SP checks" date="2014-07-28T18:04:00.247-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:06:29.999-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5481 - Updated to remove SP checks." date="2014-08-07T14:51:00.976-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-25T04:01:51.142-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 5.01,SP4 on Win2k">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3860.1000" test_ref="oval:org.mitre.oval:tst:7584"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win 2k">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1607" test_ref="oval:org.mitre.oval:tst:7696"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win XP">
          <extend_definition comment="Microsoft Windows XP is installed" definition_ref="oval:org.mitre.oval:def:105"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2900.3268" test_ref="oval:org.mitre.oval:tst:7834"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win 2003 or Win XP X64">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.3064" test_ref="oval:org.mitre.oval:tst:7573"/>
          <criteria operator="OR" comment="Win XP X64/ Win 2K3">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win 2003 / Win XP X64">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.4210" test_ref="oval:org.mitre.oval:tst:7792"/>
          <criteria operator="OR" comment="Win XP X64 / Win 2K3">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 7 on Win 2003 platforms">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="Win XP / Win 2K3 and IE 7">
            <extend_definition comment="Microsoft Windows XP is installed" definition_ref="oval:org.mitre.oval:def:105"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR / GDR">
            <criterion comment="the version of mshtml.dll is less than 7.0.6000.16608" test_ref="oval:org.mitre.oval:tst:7827"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.20733" test_ref="oval:org.mitre.oval:tst:44297"/>
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 7 on Win Vista platforms">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="Windows Vista 32/ 64 bit">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR / GDR">
            <criterion comment="the version of mshtml.dll is less than 7.0.6000.16609" test_ref="oval:org.mitre.oval:tst:7396"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.20734" test_ref="oval:org.mitre.oval:tst:44122"/>
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:548" version="4" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP4 Zone Restrictions Bypass via XML Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0817" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0817"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions and read arbitrary files via an XML object.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for Windows 2000 sp4 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp4 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed ste:2614: set datatype to version.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:54:00.319-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:59:39.731-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:45.555-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:54.500-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:22.682-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3810.1700" negate="false" test_ref="oval:org.mitre.oval:tst:2690"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5475" version="12" class="vulnerability">
      <metadata>
        <title>ActiveX Object Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1086" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1086"/>
        <description>The HxTocCtrl ActiveX control (hxvz.dll), as used in Microsoft Internet Explorer 5.01 SP4 and 6 SP1, in Windows XP SP2, Server 2003 SP1 and SP2, Vista SP1, and Server 2008, allows remote attackers to execute arbitrary code via malformed arguments, which triggers memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-04-08T16:04:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-04-11T14:11:51.428-04:00">DRAFT</status_change>
            <status_change date="2008-04-28T04:00:20.467-04:00">INTERIM</status_change>
            <status_change date="2008-05-19T04:00:20.699-04:00">ACCEPTED</status_change>
            <modified comment="Fixed comment for tst:7420." date="2010-09-23T21:03:00.017-04:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2010-09-23T21:14:06.633-04:00">INTERIM</status_change>
            <status_change date="2010-10-11T04:00:07.533-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5475 - Corrected and reorganized criteria" date="2011-01-27T16:31:00.373-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2011-01-27T16:48:22.384-05:00">INTERIM</status_change>
            <status_change date="2011-02-14T04:00:03.007-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5475 - def:5475, Added compatibility flag criteria check &amp; updated obj:5465 to have name." date="2011-11-04T11:00:00.503-04:00">
              <contributor organization="SecPod Technologies">Pradeep R B</contributor>
            </modified>
            <status_change date="2011-11-04T11:02:05.631-04:00">INTERIM</status_change>
            <status_change date="2011-11-21T04:13:11.759-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:3992 - modified vulnerabilities ofÂ MS Visual C++ Â  (winsxs folder checks were modified)" date="2014-04-17T13:09:00.881-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-04-17T13:11:52.849-04:00">INTERIM</status_change>
            <status_change date="2014-05-05T04:00:25.906-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5475 - extended definitions of OS are without SP checks" date="2014-07-28T18:03:00.291-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:04:50.696-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:05:57.815-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Vulnerable OS">
          <criteria operator="AND" comment="Windows 2000 with IE 5.01">
            <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
            <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          </criteria>
          <criteria operator="AND" comment="Windows 2000 with IE 6">
            <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
            <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          </criteria>
          <extend_definition comment="Microsoft Windows XP is installed" definition_ref="oval:org.mitre.oval:def:105"/>
          <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
          <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
          <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
        </criteria>
        <criteria operator="OR" comment="Vulnerable Compatibility Flag">
          <criterion negate="true" comment="HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{22FD7C0A-850C-4A53-9821-0B0915C96139} does not exist" test_ref="oval:org.mitre.oval:tst:7420"/>
          <criterion comment="HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{22FD7C0A-850C-4A53-9821-0B0915C96139}!Compatibility Flags is not equal to 0x00000400" test_ref="oval:org.mitre.oval:tst:77519"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5457" version="4" class="vulnerability">
      <metadata>
        <title>Embedded OpenType Font Heap Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0231" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0231"/>
        <description>The Embedded OpenType (EOT) Font Engine (T2EMBED.DLL) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted name table in a data record that triggers an integer truncation and a heap-based buffer overflow, aka "Embedded OpenType Font Heap Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-07-14T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-07-20T15:51:25.316-04:00">DRAFT</status_change>
            <status_change date="2009-08-10T04:00:03.029-04:00">INTERIM</status_change>
            <status_change date="2009-08-31T04:00:03.652-04:00">ACCEPTED</status_change>
            <modified comment="Added criteria to test for Windows Vista SP1 and Windows Server 2008 SP1 GDR version. Updated comments for multiple criteria." date="2010-01-19T09:46:00.393-05:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2010-01-19T09:50:00.400-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:02.962-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5457 - Updated several tests to reflect last revision changes from ms09-029." date="2011-10-12T14:31:00.307-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-10-12T14:32:37.264-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:04:09.282-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4 or later">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Fontsub.dll is less than 5.0.2195.7318" test_ref="oval:org.mitre.oval:tst:9808"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="the version of Fontsub.dll is less than 5.1.2600.3607" test_ref="oval:org.mitre.oval:tst:10077"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of Fontsub.dll is less than 5.1.2600.5853" test_ref="oval:org.mitre.oval:tst:9964"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64">
          <criteria operator="OR" comment="Check for Windows XP (x64) SP2 or Windows 2003">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of Fontsub.dll is less than 5.2.3790.4559" test_ref="oval:org.mitre.oval:tst:10138"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64">
          <criteria operator="OR" comment="Check for Windows Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR check">
            <criterion comment="the version of Fontsub.dll is less than 6.0.6000.16870" test_ref="oval:org.mitre.oval:tst:10238"/>
            <criteria operator="AND" comment="Check for Fontsub.dll LDR version">
              <criterion comment="the version of Fontsub.dll is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:10116"/>
              <criterion comment="the version of Fontsub.dll is less than 6.0.6000.21067" test_ref="oval:org.mitre.oval:tst:10110"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP1 x86/x64, Server 2008 32bit/x64/ia64">
          <criteria operator="OR" comment="Check for Windows Vista SP1 or Windows 2008">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR check">
            <criterion comment="the version of Fontsub.dll is less than 6.0.6001.18272" test_ref="oval:org.mitre.oval:tst:9933"/>
            <criteria operator="AND" comment="Check for Fontsub.dll LDR version">
              <criterion comment="the version of Fontsub.dll is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9819"/>
              <criterion comment="the version of Fontsub.dll is less than 6.0.6001.22450" test_ref="oval:org.mitre.oval:tst:9668"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64">
          <criteria operator="OR" comment="Check for Windows Vista SP2 or Windows 2008 SP2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR check">
            <criterion comment="the version of Fontsub.dll is less than 6.0.6002.18051" test_ref="oval:org.mitre.oval:tst:9958"/>
            <criteria operator="AND" comment="Check for Fontsub.dll LDR version">
              <criterion comment="the version of Fontsub.dll is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10029"/>
              <criterion comment="the version of Fontsub.dll is less than 6.0.6002.22152" test_ref="oval:org.mitre.oval:tst:9813"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5441" version="3" class="vulnerability">
      <metadata>
        <title>GDI Heap Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1083" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1083"/>
        <description>Heap-based buffer overflow in the CreateDIBPatternBrushPt function in GDI in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, and Server 2008 allows remote attackers to execute arbitrary code via an EMF or WMF image file with a malformed header that triggers an integer overflow, aka "GDI Heap Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-04-08T16:04:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-04-11T14:11:48.093-04:00">DRAFT</status_change>
            <status_change date="2008-04-28T04:00:17.889-04:00">INTERIM</status_change>
            <status_change date="2008-05-19T04:00:17.846-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5441 - Added LDR critiera &amp; itanium support for Win 2003 &amp; 2008" date="2011-10-25T14:31:00.257-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2011-10-25T14:34:42.088-04:00">INTERIM</status_change>
            <status_change date="2011-11-14T04:00:32.001-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="win 2000/version">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Gdi32.dll version is less than 5.0.2195.7153" test_ref="oval:org.mitre.oval:tst:7313"/>
        </criteria>
        <criteria operator="AND" comment="win XP/version">
          <criterion comment="Gdi32.dll version is less than 5.1.2600.3316" test_ref="oval:org.mitre.oval:tst:7477"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
        </criteria>
        <criteria operator="AND" comment="win XP/server 2003 sp1/version">
          <criterion comment="Gdi32.dll version is less than 5.2.3790.3091" test_ref="oval:org.mitre.oval:tst:7867"/>
          <criteria operator="OR" comment="OS check">
            <extend_definition comment="Microsoft Windows XP Professional x64 Edition SP1 is installed" definition_ref="oval:org.mitre.oval:def:720"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:4386"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="win XP sp2/server 2003 sp2/version">
          <criterion comment="Gdi32.dll version is less than 5.2.3790.4237" test_ref="oval:org.mitre.oval:tst:7979"/>
          <criteria operator="OR" comment="OS check">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="vista/version">
          <criteria operator="OR" comment="OS check">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="GDR/LDR">
            <criterion comment="Gdi32.dll version is less than 6.0.6000.16643" test_ref="oval:org.mitre.oval:tst:7866"/>
            <criteria operator="AND" comment="LDR range">
              <criterion comment="Check if the version of Gdi32.dll is greater than or equal to 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:44319"/>
              <criterion comment="Check if the version of Gdi32.dll is less than 6.0.6000.20777" test_ref="oval:org.mitre.oval:tst:44191"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="vista sp1/server 2008/version">
          <criteria operator="OR" comment="OS check">
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
          </criteria>
          <criteria operator="OR" comment="GDR/LDR">
            <criterion comment="Gdi32.dll version is less than 6.0.6001.18023" test_ref="oval:org.mitre.oval:tst:7782"/>
            <criteria operator="AND" comment="LDR range">
              <criterion comment="Check if the version of Gdi32.dll is greater than or equal to 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:43984"/>
              <criterion comment="Check if the version of Gdi32.dll is less than 6.0.6001.22120" test_ref="oval:org.mitre.oval:tst:44324"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5440" version="1" class="vulnerability">
      <metadata>
        <title>Windows Kernel Invalid Pointer Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0083" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0083"/>
        <description>The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 does not properly handle invalid pointers, which allows local users to gain privileges via an application that triggers use of a crafted pointer, aka "Windows Kernel Invalid Pointer Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-03-10T16:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-03-13T20:24:03.481-04:00">DRAFT</status_change>
            <status_change date="2009-03-30T04:00:16.206-04:00">INTERIM</status_change>
            <status_change date="2009-04-20T04:00:15.190-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of win32k.sys is less than 5.0.2195.7251" test_ref="oval:org.mitre.oval:tst:8764"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="the version of win32k.sys is less than 5.1.2600.3521" test_ref="oval:org.mitre.oval:tst:9733"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of win32k.sys is less than 5.1.2600.5756" test_ref="oval:org.mitre.oval:tst:9386"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of win32k.sys is less than 5.2.3790.3291" test_ref="oval:org.mitre.oval:tst:9426"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:4386"/>
            <extend_definition comment="Microsoft Windows XP x64 Edition SP1 is installed" definition_ref="oval:org.mitre.oval:def:720"/>
          </criteria>
          <criterion comment="the version of win32k.sys is less than 5.2.3790.3291" test_ref="oval:org.mitre.oval:tst:9426"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5437" version="4" class="vulnerability">
      <metadata>
        <title>Windows Kernel Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1084" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1084"/>
        <description>Unspecified vulnerability in the kernel in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, through Vista SP1, and Server 2008 allows local users to execute arbitrary code via unknown vectors related to improper input validation.  NOTE: it was later reported that one affected function is NtUserFnOUTSTRING in win32k.sys.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-04-08T16:04:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-04-11T14:11:49.831-04:00">DRAFT</status_change>
            <status_change date="2008-04-28T04:00:17.183-04:00">INTERIM</status_change>
            <status_change date="2008-05-19T04:00:16.750-04:00">ACCEPTED</status_change>
            <modified comment="Added new Platform: Microsoft Windows Server 2008" date="2008-10-16T13:45:00.348-04:00">
              <contributor organization="Secure Elements, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2008-10-16T13:46:31.382-04:00">INTERIM</status_change>
            <status_change date="2008-11-03T04:00:17.741-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5437 - Updated def:5437 to support Win2003 &amp; Win2008 itanium. Added LDR check for vista &amp; 2008" date="2011-10-28T21:07:00.604-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2011-10-28T21:08:50.902-04:00">INTERIM</status_change>
            <status_change date="2011-11-14T04:00:31.184-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Win32k.sys version is less than 5.0.2195.7154" test_ref="oval:org.mitre.oval:tst:7929"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows XP SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="Win32k.sys version is less than 5.1.2600.3335" test_ref="oval:org.mitre.oval:tst:7693"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows XP x64 SP1/Server 2003 SP1 x86/x64/ia-64">
          <criteria operator="OR" comment="Windows XP x64 SP1/Server 2003 SP1 x86/x64/ia-64">
            <extend_definition comment="Microsoft Windows XP Professional x64 Edition SP1 is installed" definition_ref="oval:org.mitre.oval:def:720"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:4386"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
          </criteria>
          <criterion comment="Win32k.sys version is less than 5.2.3790.3106" test_ref="oval:org.mitre.oval:tst:8004"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows XP x64 SP2/Server 2003 SP2 x86/x64/ia-64">
          <criteria operator="OR" comment="Windows XP x64 SP2/Server 2003 SP2 x86/x64/ia-64">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="Win32k.sys version is less than 5.2.3790.4256" test_ref="oval:org.mitre.oval:tst:7714"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Vista (32-bit)/(x64)">
          <criteria operator="OR" comment="Windows Vista (32-bit)/(x64)">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criterion comment="Win32k.sys version is less than 6.0.6000.16646" test_ref="oval:org.mitre.oval:tst:7448"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="the version of win32k.sys is greater than 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9977"/>
              <criterion comment="Check if version of win32k.sys is less than 6.0.6000.20782" test_ref="oval:org.mitre.oval:tst:44480"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Vista SP1 (32-bit)/(x64) /Server 2008 x86/x64/ia-64">
          <criteria operator="OR" comment="Windows Vista SP1 (32-bit)/(x64) /Server 2008 x86/x64/ia-64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criterion comment="Win32k.sys version is less than 6.0.6001.18027" test_ref="oval:org.mitre.oval:tst:7954"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="the version of win32k.sys is greater than or equal to 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:43082"/>
              <criterion comment="Check if version of win32k.sys is less than 6.0.6001.22125" test_ref="oval:org.mitre.oval:tst:44302"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:542" version="3" class="vulnerability">
      <metadata>
        <title>IE v5.5 Malformed PNG Image File Failure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1185" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1185"/>
        <description>Internet Explorer 5.01 through 6.0 does not properly check certain parameters of a PNG file when opening it, which allows remote attackers to cause a denial of service (crash) by triggering a heap-based buffer overflow using invalid length codes during decompression, aka "Malformed PNG Image File Failure."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-27T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:53.133-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:22.562-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Internet Explorer 5.5 Installed">
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3078"/>
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3077"/>
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3076"/>
          <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
        </criteria>
        <criterion comment="the version of mshtml.dll is less than 5.50.4922.900" negate="false" test_ref="oval:org.mitre.oval:tst:2786"/>
        <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
        <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
        <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5412" version="1" class="vulnerability">
      <metadata>
        <title>Malformed AVI Header Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1545" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1545"/>
        <description>Unspecified vulnerability in Avifil32.dll in the Windows Media file handling functionality in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a malformed header in a crafted AVI file, aka "Malformed AVI Header Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-07-28T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-08-19T14:58:07.512-04:00">DRAFT</status_change>
            <status_change date="2009-09-07T04:00:03.418-04:00">INTERIM</status_change>
            <status_change date="2009-09-28T04:00:04.302-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Avifil32.dll is less than 5.0.2195.7316" test_ref="oval:org.mitre.oval:tst:10408"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="the version of Avifil32.dll is less than 5.1.2600.3585" test_ref="oval:org.mitre.oval:tst:10705"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of Avifil32.dll is less than 5.1.2600.5827" test_ref="oval:org.mitre.oval:tst:10660"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of Avifil32.dll is less than 5.2.3790.4527" test_ref="oval:org.mitre.oval:tst:10576"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="the version of Avifil32.dll is less than 6.0.6000.16868" test_ref="oval:org.mitre.oval:tst:10489"/>
          <criterion comment="the version of Avifil32.dll is greater than or equal 6.0.6000.16000" test_ref="oval:org.mitre.oval:tst:10678"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="the version of Avifil32.dll is less than 6.0.6000.21065" test_ref="oval:org.mitre.oval:tst:10465"/>
          <criterion comment="the version of Avifil32.dll is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:10566"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of Avifil32.dll is less than 6.0.6001.18270" test_ref="oval:org.mitre.oval:tst:10712"/>
          <criterion comment="the version of Avifil32.dll is greater than or equal 6.0.6001.18000" test_ref="oval:org.mitre.oval:tst:10375"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="the version of Avifil32.dll is less than 6.0.6001.22447" test_ref="oval:org.mitre.oval:tst:10665"/>
          <criterion comment="the version of Avifil32.dll is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:10163"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="the version of Avifil32.dll is less than 6.0.6002.18049" test_ref="oval:org.mitre.oval:tst:10707"/>
          <criterion comment="the version of Avifil32.dll is greater than or equal 6.0.6002.18000" test_ref="oval:org.mitre.oval:tst:10051"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criterion comment="the version of Avifil32.dll is less than 6.0.6002.22150" test_ref="oval:org.mitre.oval:tst:10627"/>
          <criterion comment="the version of Avifil32.dll is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10506"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5408" version="4" class="vulnerability">
      <metadata>
        <title>LSASS Bypass Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference ref_id="CVE-2007-5352" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5352" source="CVE"/>
        <description>Unspecified vulnerability in Local Security Authority Subsystem Service (LSASS) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2 allows local users to gain privileges via a crafted local procedure call (LPC) request.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-01-08T14:23:12">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-02-18T04:00:09.937-05:00">INTERIM</status_change>
            <status_change date="2008-03-10T04:00:15.098-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5408 - October Patch Tuesday" date="2011-10-14T15:51:00.795-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-10-14T15:52:17.005-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:04:08.775-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of lsasrv.dll is less than 5.0.2195.7147" test_ref="oval:org.mitre.oval:tst:7704"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows XP SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of lsasrv.dll is less than 5.1.2600.3249" test_ref="oval:org.mitre.oval:tst:7389"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows XP x64 SP1/Server 2003 SP1 x86/x64/ia-64">
          <criteria operator="OR" comment="Windows XP x64 SP1/Server 2003 SP1 x86/x64/ia-64">
            <extend_definition comment="Microsoft Windows XP Professional x64 Edition SP1 is installed" definition_ref="oval:org.mitre.oval:def:720"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:4386"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
          </criteria>
          <criterion comment="the version of lsasrv.dll is less than 5.2.3790.3041" test_ref="oval:org.mitre.oval:tst:7803"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows XP x64 SP2/Server 2003 SP2 x86/x64/ia-64">
          <criteria operator="OR" comment="Windows XP x64 SP2/Server 2003 SP2 x86/x64/ia-64">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of lsasrv.dll is less than 5.2.3790.4186" test_ref="oval:org.mitre.oval:tst:7676"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:540" class="vulnerability" version="1">
      <metadata>
        <title>OLE Dialog Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Interactive Training</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0026" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0026"/>
        <description>The OLE Dialog component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1 allows user-assisted remote attackers to execute arbitrary code via an RTF file with a malformed OLE object that triggers memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-02-14T09:49:32">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-02-16T21:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:17:21.048-04:00">INTERIM</status_change>
            <status_change date="2007-04-10T13:44:26.598-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Win2K,SP4" operator="AND">
          <extend_definition comment="Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Oledlg.dll is less than 5.0.2195.7114" test_ref="oval:org.mitre.oval:tst:3179"/>
        </criteria>
        <criteria comment="WinXP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of Oledlg.dll is less than 5.1.2600.3016" test_ref="oval:org.mitre.oval:tst:3286"/>
        </criteria>
        <criteria comment="WinXP,SP1 (64-bit)" operator="AND">
          <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="the version of Oledlg.dll is less than 5.2.3790.2813" test_ref="oval:org.mitre.oval:tst:3711"/>
        </criteria>
        <criteria comment="S03-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="the version of Oledlg.dll is less than 5.2.3790.601" test_ref="oval:org.mitre.oval:tst:3967"/>
        </criteria>
        <criteria comment="S03,SP1" operator="AND">
          <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of Oledlg.dll is less than 5.2.3790.2813" test_ref="oval:org.mitre.oval:tst:3711"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5396" version="11" class="vulnerability">
      <metadata>
        <title>Property Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference ref_id="CVE-2008-0077" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0077" source="CVE"/>
        <description>Use-after-free vulnerability in Microsoft Internet Explorer 6 SP1, 6 SP2, and and 7 allows remote attackers to execute arbitrary code by assigning malformed values to certain properties, as demonstrated using the by property of an animateMotion SVG element, aka "Property Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-02-13T10:19:01">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-02-13T16:35:14.098-05:00">DRAFT</status_change>
            <modified date="2008-03-02T04:44:54" comment="Added file check to ensure a full installation.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <modified comment="Fixed typo" date="2008-03-11T09:58:00.328-04:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2008-03-31T04:00:08.351-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5396 - Added LDR support and removed IE 5.01 criteria where appropriate" date="2011-10-25T14:22:00.696-04:00">
              <contributor organization="SecPod Technologies">Pooja Shetty</contributor>
            </modified>
            <status_change date="2011-10-25T14:25:20.129-04:00">INTERIM</status_change>
            <status_change date="2011-11-14T04:00:30.461-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5396 - Correcting incorrect references to 64-bit Itanium XP." date="2012-08-23T17:47:00.168-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-08-23T17:52:15.487-04:00">INTERIM</status_change>
            <status_change date="2012-09-10T04:00:58.537-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:39.645-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:22.437-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5396 - extended definitions of OS are without SP checks" date="2014-07-28T18:04:00.247-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:06:31.724-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5396 - Updated to remove SP checks." date="2014-08-07T14:51:00.976-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-25T04:01:50.742-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 on Win 2k">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1607" test_ref="oval:org.mitre.oval:tst:7696"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win XP">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2900.3268" test_ref="oval:org.mitre.oval:tst:7834"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win 2003 or Win XP X64">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.3064" test_ref="oval:org.mitre.oval:tst:7573"/>
          <criteria operator="OR" comment="Win XP X64/ Win 2K3">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win 2003 / Win XP X64">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.4210" test_ref="oval:org.mitre.oval:tst:7792"/>
          <criteria operator="OR" comment="Win XP X64 / Win 2K3">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 7 on Win 2003 platforms">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="Win XP / Win 2K3 and IE 7">
            <extend_definition comment="Microsoft Windows XP is installed" definition_ref="oval:org.mitre.oval:def:105"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR / GDR">
            <criterion comment="the version of mshtml.dll is less than 7.0.6000.16608" test_ref="oval:org.mitre.oval:tst:7827"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.20733" test_ref="oval:org.mitre.oval:tst:44297"/>
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 7 on Win Vista platforms">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="Windows Vista 32/ 64 bit">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR / GDR">
            <criterion comment="the version of mshtml.dll is less than 7.0.6000.16609" test_ref="oval:org.mitre.oval:tst:7396"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.20734" test_ref="oval:org.mitre.oval:tst:44122"/>
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5389" version="3" class="vulnerability">
      <metadata>
        <title>Internet Information Services Local Privilege Elevation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Information Server (IIS) 5.0</product>
          <product>Microsoft Internet Information Server (IIS) 5.1</product>
          <product>Microsoft Internet Information Server (IIS) 6.0</product>
          <product>Microsoft Internet Information Server (IIS) 7.0</product>
        </affected>
        <reference ref_id="CVE-2008-0074" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0074" source="CVE"/>
        <description>Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows local users to gain privileges via unknown vectors related to file change notifications in the TPRoot, NNTPFile\Root, or WWWRoot folders.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-02-14T10:00:19">
              <contributor organization="Secure Elements, Inc.">Jeff Ito</contributor>
            </submitted>
            <status_change date="2008-02-14T14:55:52.136-05:00">DRAFT</status_change>
            <status_change date="2008-03-03T04:00:15.499-05:00">INTERIM</status_change>
            <status_change date="2008-03-24T04:00:45.715-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5389 - def:5389 updated with Win2003 SP1 and SP2 itanium support, Win2003 x64 inclusion &amp; added LDR version check for vista." date="2011-10-28T21:07:00.514-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2011-10-28T21:11:41.465-04:00">INTERIM</status_change>
            <status_change date="2011-11-14T04:00:29.721-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable IIS 5.0">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft IIS 5.0 is installed" definition_ref="oval:org.mitre.oval:def:731"/>
          <criterion comment="the version of infocomm.dll is less than 5.0.2195.7147" test_ref="oval:org.mitre.oval:tst:7595"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable IIS 5.1">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Microsoft IIS 5.1 is installed" definition_ref="oval:org.mitre.oval:def:460"/>
          <criterion comment="the version of infocomm.dll is less than 6.0.2600.3290" test_ref="oval:org.mitre.oval:tst:7363"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable IIS 6.0">
          <extend_definition comment="Microsoft IIS 6.0 is installed" definition_ref="oval:org.mitre.oval:def:227"/>
          <criteria operator="OR" comment="Vulnerable OS">
            <criteria operator="AND" comment="Vulnerable Windows XP x64 SP1/Server 2003 SP1 x86/x64/ia-64">
              <criteria operator="OR" comment="Windows XP x64 SP1/Server 2003 SP1 x86/x64/ia-64">
                <extend_definition comment="Microsoft Windows XP Professional x64 Edition SP1 is installed" definition_ref="oval:org.mitre.oval:def:720"/>
                <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
                <extend_definition comment="Microsoft Windows Server 2003 SP1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:4386"/>
                <extend_definition comment="Microsoft Windows Server 2003 SP1 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
              </criteria>
              <criterion comment="the version of infocomm.dll is less than 6.0.3790.3068" test_ref="oval:org.mitre.oval:tst:7576"/>
            </criteria>
            <criteria operator="AND" comment="Vulnerable Windows XP x64 SP2/Server 2003 SP2 x86/x64/ia-64">
              <criteria operator="OR" comment="Windows XP x64 SP2/Server 2003 SP2 x86/x64/ia-64">
                <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
                <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
                <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
              </criteria>
              <criterion comment="the version of infocomm.dll is less than 6.0.3790.4215" test_ref="oval:org.mitre.oval:tst:7802"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable IIS 7.0">
          <extend_definition comment="Microsoft IIS 7.0 is installed" definition_ref="oval:org.mitre.oval:def:5377"/>
          <criteria operator="OR" comment="Vulnerable Windows Vista (32-bit)/x64">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criterion comment="the version of infocomm.dll is less than 7.0.6000.16576" test_ref="oval:org.mitre.oval:tst:7747"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if version of infocomm.dll is less than 7.0.6000.20698" test_ref="oval:org.mitre.oval:tst:44490"/>
              <criterion comment="Check if version of infocomm.dll is greater than or equal to 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:44092"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5377" version="3" class="inventory">
      <metadata>
        <title>Microsoft IIS 7.0 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft IIS 7.0</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:iis:7.0"/>
        <description>The application Microsoft IIS 7.0 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-02-14T10:00:19">
              <contributor organization="Secure Elements, Inc.">Jeff Ito</contributor>
            </submitted>
            <status_change date="2008-02-14T14:55:51.694-05:00">DRAFT</status_change>
            <status_change date="2008-03-03T04:00:13.826-05:00">INTERIM</status_change>
            <status_change date="2008-03-24T04:00:43.767-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5377 - product info corrected" date="2015-04-15T12:33:00.646-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-04-15T12:36:19.806-04:00">INTERIM</status_change>
            <status_change date="2015-05-04T04:00:20.226-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="IIS Major Version equals 7" test_ref="oval:org.mitre.oval:tst:7848"/>
        <criterion comment="IIS Minor Version equals 0" test_ref="oval:org.mitre.oval:tst:164"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5388" version="6" class="vulnerability">
      <metadata>
        <title>OLE Heap Overrun Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Visual Basic 6.0</product>
        </affected>
        <reference ref_id="CVE-2007-0065" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0065" source="CVE"/>
        <description>Heap-based buffer overflow in Object Linking and Embedding (OLE) Automation in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, Office 2004 for Mac, and Visual basic 6.0 SP6 allows remote attackers to execute arbitrary code via a crafted script request.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-02-12T17:17:09">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-02-13T16:35:10.605-05:00">DRAFT</status_change>
            <status_change date="2008-03-03T04:00:14.870-05:00">INTERIM</status_change>
            <status_change date="2008-03-24T04:00:45.023-04:00">ACCEPTED</status_change>
            <modified comment="Removed redundant tests" date="2008-04-11T13:56:00.473-04:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2008-04-11T13:58:31.499-04:00">INTERIM</status_change>
            <status_change date="2008-04-28T04:00:16.278-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5388 - def:5388, Inclusion of Win2003 IA-64 SP1, SP2 &amp; LDR support" date="2011-11-15T14:44:00.580-05:00">
              <contributor organization="SecPod Technologies">Pradeep R B</contributor>
            </modified>
            <status_change date="2011-11-15T14:46:15.869-05:00">INTERIM</status_change>
            <status_change date="2011-12-05T04:00:25.751-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5388 - New inventory definition for VB6, and updates to definitions incorrectly checking VBA inventory instead of VB6." date="2012-10-25T16:38:00.742-04:00">
              <contributor organization="SecPod Technologies">Pradeep R B</contributor>
            </modified>
            <status_change date="2012-10-25T16:58:35.584-04:00">INTERIM</status_change>
            <status_change date="2012-11-12T04:00:31.279-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of oleaut32.dll is less than 2.40.4532.0" test_ref="oval:org.mitre.oval:tst:7519"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows XP SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of oleaut32.dll is less than 5.1.2600.3266" test_ref="oval:org.mitre.oval:tst:7828"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows XP x64 SP1/Server 2003 (x86)/(x64)/(ia-64) SP1">
          <criteria operator="OR" comment="Windows XP x64 SP1/Server 2003 (x86)/(x64)/(ia-64) SP1">
            <extend_definition comment="Microsoft Windows XP Professional x64 Edition SP1 is installed" definition_ref="oval:org.mitre.oval:def:720"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:4386"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
          </criteria>
          <criterion comment="the version of oleaut32.dll is less than 5.2.3790.3057" test_ref="oval:org.mitre.oval:tst:7666"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows XP x64 SP2/Server 2003 (x86)/(x64)/(ia-64) SP2">
          <criteria operator="OR" comment="Windows XP x64 SP2/Server 2003 (x86)/(x64)/(ia-64) SP2">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of oleaut32.dll is less than 5.2.3790.4202" test_ref="oval:org.mitre.oval:tst:7548"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Vista (32-bit)/(x64)">
          <criteria operator="OR" comment="Windows Vista (32-bit)/(x64)">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criterion comment="the version of oleaut32.dll is less than 6.0.6000.16607" test_ref="oval:org.mitre.oval:tst:7832"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="the version of oleaut32.dll is less than 6.0.6000.20732" test_ref="oval:org.mitre.oval:tst:7768"/>
              <criterion comment="Check if version of oleaut32.dll is greater than or equal to 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:77478"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Visual Basic 6.0">
          <criteria operator="OR" comment="Vulnerable file version">
            <criterion comment="the version of oleaut32.dll is less than 2.40.4532.0" test_ref="oval:org.mitre.oval:tst:7519"/>
            <criterion comment="the version of oleaut32.dll is less than 5.2.3790.3057" test_ref="oval:org.mitre.oval:tst:7666"/>
            <criterion comment="the version of oleaut32.dll is less than 5.2.3790.4202" test_ref="oval:org.mitre.oval:tst:7548"/>
            <criterion comment="the version of oleaut32.dll is less than 6.0.6000.20732" test_ref="oval:org.mitre.oval:tst:7768"/>
            <criterion comment="the version of oleaut32.dll is less than 5.1.2600.3266" test_ref="oval:org.mitre.oval:tst:7828"/>
            <criterion comment="Check if version of oleaut32.dll is less than 2.40.4520.0" test_ref="oval:org.mitre.oval:tst:77578"/>
            <criterion comment="Check if version of oleaut32.dll is less than 5.2.3790.727" test_ref="oval:org.mitre.oval:tst:77486"/>
            <criterion comment="Check if version of oleaut32.dll is less than 3.50.5022.0" test_ref="oval:org.mitre.oval:tst:77199"/>
          </criteria>
          <extend_definition comment="Microsoft Visual Basic 6.0 is installed" definition_ref="oval:org.mitre.oval:def:15369"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15369" version="5" class="inventory">
      <metadata>
        <title>Microsoft Visual Basic 6.0 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Visual Basic 6.0</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:visual_basic:6.0"/>
        <description>The application Microsoft Visual Basic 6.0 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2012-10-25T05:39:06">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-10-25T16:55:43.428-04:00">DRAFT</status_change>
            <status_change date="2012-11-12T04:00:10.103-05:00">INTERIM</status_change>
            <status_change date="2012-12-03T04:00:07.178-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:15369 - corrected inventory-definition for Visual Basic 6.0" date="2013-06-11T12:18:00.504-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-11T12:20:21.617-04:00">INTERIM</status_change>
            <status_change date="2013-07-01T04:00:17.631-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Check if file vb6.exe exists" test_ref="oval:org.mitre.oval:tst:80295"/>
        <criterion comment="Check if HKLM\SOFTWARE\Microsoft\VisualStudio\6.0\Setup\Microsoft Visual Basic!ProductDir exists" test_ref="oval:org.mitre.oval:tst:80783"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5380" version="3" class="vulnerability">
      <metadata>
        <title>DNS Cache Poisoning Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1454" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1454"/>
        <description>Unspecified vulnerability in Microsoft DNS in Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008 allows remote attackers to conduct cache poisoning attacks via unknown vectors related to accepting "records from a response that is outside the remote server's authority," aka "DNS Cache Poisoning Vulnerability," a different vulnerability than CVE-2008-1447.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-08T14:18:00">
              <contributor organization="Secure Elements, Inc.">Jeff Ito</contributor>
            </submitted>
            <status_change date="2008-07-11T10:55:58.881-04:00">DRAFT</status_change>
            <status_change date="2008-07-28T04:00:12.161-04:00">INTERIM</status_change>
            <status_change date="2008-08-18T04:00:25.615-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5380 - Updated def:5725 to support DNS client too. Updated def:5380 to add LDR version check." date="2011-10-28T20:15:00.076-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2011-10-28T20:23:14.562-04:00">INTERIM</status_change>
            <status_change date="2011-11-14T04:00:28.614-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win 2K SP4 and vulnerable version of file">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Dns.exe version is less than 5.0.2195.7162" test_ref="oval:org.mitre.oval:tst:8430"/>
        </criteria>
        <criteria operator="AND" comment="Win 2k3 SP1 and vulnerable version of server file">
          <criteria operator="OR" comment="Win 2K3 SP1 (X86/ X64/IA64)">
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
          </criteria>
          <criterion comment="dns.exe version is less than 5.2.3790.3161" test_ref="oval:org.mitre.oval:tst:8599"/>
        </criteria>
        <criteria operator="AND" comment="Win 2k3 SP2 and vulnerable version of server file">
          <criteria operator="OR" comment="Win 2K3 SP2 (X86/ X64/IA64)">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="dns.exe version is less than 5.2.3790.4318" test_ref="oval:org.mitre.oval:tst:8535"/>
        </criteria>
        <criteria operator="AND" comment="Win 2k8 and vulnerable version of server file">
          <criteria operator="OR" comment="Win 2K8 32/64 bit">
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR / GDR">
            <criterion comment="Check if the version of dns.exe is less than 6.0.6001.18081" test_ref="oval:org.mitre.oval:tst:44213"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of dns.exe is greater than or equal to 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:44475"/>
              <criterion comment="dns.exe version is less than 6.0.6001.22192" test_ref="oval:org.mitre.oval:tst:8558"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5366" version="5" class="vulnerability">
      <metadata>
        <title>Uninitialized Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2256" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2256"/>
        <description>Microsoft Internet Explorer 5.01, 6, and 7 does not properly handle objects that have been incorrectly initialized or deleted, which allows remote attackers to cause a denial of service (crash) and execute arbitrary code via unknown vectors, aka "Uninitialized Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-13T09:28:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-08-14T15:03:13.330-04:00">DRAFT</status_change>
            <status_change date="2008-09-01T04:00:55.744-04:00">INTERIM</status_change>
            <status_change date="2008-09-22T04:00:23.167-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:9018 - Included LDR support &amp; added new state to match correct version." date="2011-10-25T14:07:00.717-04:00">
              <contributor organization="SecPod Technologies">Pooja Shetty</contributor>
            </modified>
            <status_change date="2011-10-25T14:12:07.398-04:00">INTERIM</status_change>
            <status_change date="2011-11-14T04:00:27.165-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5366 - extended definitions of OS are without SP checks" date="2014-07-28T17:42:00.658-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:44:51.508-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:05:57.556-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win 2K + IE6 vulnerable version">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1613" test_ref="oval:org.mitre.oval:tst:8781"/>
        </criteria>
        <criteria operator="AND" comment="Win 2K + IE 5.01">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="Mshtml.dll version is less than 5.0.3866.2000" test_ref="oval:org.mitre.oval:tst:8949"/>
        </criteria>
        <criteria operator="AND" comment="Win XP + IE 6">
          <extend_definition comment="Microsoft Windows XP is installed" definition_ref="oval:org.mitre.oval:def:105"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3395" test_ref="oval:org.mitre.oval:tst:8921"/>
        </criteria>
        <criteria operator="AND" comment="Win XP + IE 6">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5626" test_ref="oval:org.mitre.oval:tst:9128"/>
        </criteria>
        <criteria operator="AND" comment="Win XP /  Win 2K3 + IE 7">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="Win XP / Win 2K3">
            <extend_definition comment="Microsoft Windows XP is installed" definition_ref="oval:org.mitre.oval:def:105"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR / GDR">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16705" test_ref="oval:org.mitre.oval:tst:9018"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Check if the version mshtml.dll is less than 7.0.6000.20861" test_ref="oval:org.mitre.oval:tst:44137"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 2K3 / Win XP X64 and IE 6">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.3167" test_ref="oval:org.mitre.oval:tst:8958"/>
          <criteria operator="OR" comment="Win 2K3 / Win XP X64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win XP X64 / Win 2K3">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4324" test_ref="oval:org.mitre.oval:tst:8988"/>
          <criteria operator="OR" comment="Win 2K3 / Win XP X64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win Vista and IE7">
          <extend_definition comment="Microsoft Windows Vista is installed" definition_ref="oval:org.mitre.oval:def:228"/>
          <criteria operator="OR" comment="Check for LDR and GDR">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16711" test_ref="oval:org.mitre.oval:tst:8163"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.20868" test_ref="oval:org.mitre.oval:tst:44258"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
        </criteria>
        <criteria operator="AND" comment="Win Vista / Win 2K8 and IE7">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="Win Vista/ Win 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR /GDR">
            <criterion comment="Mshtml.dll version is less than 7.0.6001.18099" test_ref="oval:org.mitre.oval:tst:9108"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Mshtml.dll version is greater than or equal to 7.0.6001.22000" test_ref="oval:org.mitre.oval:tst:42152"/>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6001.22212" test_ref="oval:org.mitre.oval:tst:44416"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:535" version="1">
      <metadata>
        <title>Microsoft Indexing Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Indexing Service</product>
        </affected>
        <reference ref_id="CVE-2006-0032" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0032" source="CVE"/>
        <description>Cross-site scripting (XSS) vulnerability in the Indexing Service in Microsoft Windows 2000, XP, and Server 2003, when the Encoding option is set to Auto Select, allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded URL, which is injected into an error message whose charset is set to UTF-7.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-21T07:56:35">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:48.927-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:56.512-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Win2K,SP4" operator="AND">
          <extend_definition comment="Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Query.dll is less than 5.0.2195.7100" test_ref="oval:org.mitre.oval:tst:133"/>
        </criteria>
        <criteria comment="WinXP,SP1" operator="AND">
          <extend_definition comment="Windows XP, SP1 is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          <criterion comment="the version of Query.dll is less than 5.1.2600.1860" test_ref="oval:org.mitre.oval:tst:153"/>
        </criteria>
        <criteria comment="WinXP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of Query.dll is less than 5.1.2600.2935" test_ref="oval:org.mitre.oval:tst:19"/>
        </criteria>
        <criteria comment="WinXP,SP1 (64-bit)" operator="AND">
          <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="the version of Query.dll is less than 5.2.3790.2734" test_ref="oval:org.mitre.oval:tst:20"/>
        </criteria>
        <criteria comment="S03-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="the version of Query.dll is less than 5.2.3790.552" test_ref="oval:org.mitre.oval:tst:21"/>
        </criteria>
        <criteria comment="S03,SP1" operator="AND">
          <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of Query.dll is less than 5.2.3790.2734" test_ref="oval:org.mitre.oval:tst:20"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:534" version="5" class="vulnerability">
      <metadata>
        <title>IE v6.0,SP1 Function Pointer Drag and Drop Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1027" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1027"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CVE-2003-0823, aka the "Function Pointer Drag and Drop Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:52:00.000-04:00" comment="modified wft-94 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:45:56.946-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:44.635-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:46.323-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:22.343-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1400" negate="false" test_ref="oval:org.mitre.oval:tst:2579"/>
          <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5329" version="5" class="vulnerability">
      <metadata>
        <title>IE v6.0,SP1 Install Engine Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0216" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0216"/>
        <description>Integer overflow in the Install Engine (inseng.dll) for Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious website or HTML email with a long .CAB file name, which triggers the integer overflow when calculating a buffer length and leads to a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-25T04:35:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-27T01:04:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-17T10:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-27T10:50:00.000-04:00" comment="modified wft-564 - Changed test to match comment">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:46:01.772-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:44.229-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:53.347-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:22.267-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1476" negate="false" test_ref="oval:org.mitre.oval:tst:856"/>
          <criterion comment="the patch kb834707 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:855"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5320" version="4" class="vulnerability" deprecated="true">
      <metadata>
        <title>Windows HTTP Services Credential Reflection Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0550" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0550"/>
        <description>Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008; and WinINet in Microsoft Internet Explorer 5.01 SP4, 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on Windows Server 2003 SP1 and SP2, 7 on Windows Vista Gold and SP1, and 7 on Windows Server 2008; allows remote web servers to capture and replay NTLM credentials, and execute arbitrary code, via vectors related to absence of a "credential-reflection protections" opt-in step, aka "Windows HTTP Services Credential Reflection Vulnerability" and "WinINet Credential Reflection Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-04-14T16:00:00">
              <contributor organization="Gideon Technologies, Inc.">Kyle Key</contributor>
            </submitted>
            <status_change date="2009-04-17T16:45:33.785-04:00">DRAFT</status_change>
            <status_change date="2009-05-04T04:00:08.766-04:00">INTERIM</status_change>
            <status_change date="2009-05-25T04:01:34.978-04:00">ACCEPTED</status_change>
            <modified comment="Removed CVE from title. Removed Microsoft reference" date="2009-06-01T16:05:28.035-04:00">
              <contributor organization="The MITRE Corporation">Brendan Miles</contributor>
            </modified>
            <status_change date="2009-06-08T04:00:41.319-04:00">INTERIM</status_change>
            <status_change date="2009-06-29T04:00:25.753-04:00">ACCEPTED</status_change>
            <modified comment="Deprecating duplicate definition" date="2010-01-12T12:00:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2010-01-12T12:00:00.000-05:00">DEPRECATED</status_change>
            <modified comment="Edited var:306 - Added beginning anchor to local_variable used in pattern match" date="2010-05-13T15:50:00.065-04:00">
              <contributor organization="The MITRE Corporation">Mike Lah</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:var:306 - Added closing anchors for variable regex" date="2013-04-08T11:01:00.574-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="winhttp.dll version 5.1.2600.3490 or later on Windows 2000 sp4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="system32\winhttp.dll version less than 5.1.2600.3490" test_ref="oval:org.mitre.oval:tst:9822"/>
        </criteria>
        <criteria operator="AND" comment="winhttp.dll versin 5.1.2600.3494 or later on windows xp sp2 x86">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="system32\winhttp.dll version less than 5.1.2600.3494" test_ref="oval:org.mitre.oval:tst:9877"/>
        </criteria>
        <criteria operator="AND" comment="winhttp.dll versin 5.1.2600.5727 or later on windows xp sp3 x86">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="system32\winhttp.dll version less than 5.1.2600.5727" test_ref="oval:org.mitre.oval:tst:9540"/>
        </criteria>
        <criteria operator="AND" comment="winhttp.dll versin 5.2.3790.3262 or later on windows xp sp1 x64">
          <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="system32\winhttp.dll version less than 5.2.3790.3262" test_ref="oval:org.mitre.oval:tst:9795"/>
        </criteria>
        <criteria operator="AND" comment="winhttp.dll versin 5.2.3790.4427 or later on windows xp sp2 x64">
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          <criterion comment="system32\winhttp.dll version less than 5.2.3790.4427" test_ref="oval:org.mitre.oval:tst:9649"/>
        </criteria>
        <criteria operator="AND" comment="winhttp.dll versin 5.2.3790.3262 or later on windows server 2003 sp1 (x86)(x64)(ia64)">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:4386"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP1 is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
          </criteria>
          <criterion comment="Winsxs\winhttp.dll version less than 5.2.3790.3262" test_ref="oval:org.mitre.oval:tst:9580"/>
        </criteria>
        <criteria operator="AND" comment="winhttp.dll versin 5.2.3790.4427 or later on windows server 2003 sp2 (x86)(x64)(ia64)">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="Winsxs\winhttp.dll version less than 5.2.3790.4427" test_ref="oval:org.mitre.oval:tst:9985"/>
        </criteria>
        <criteria operator="AND" comment="winhttp.dll versin 6.0.6000.16786 or later on windows vista GDR (x86)(x64)">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="system32\winhttp.dll version greater than or equal 6.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9951"/>
          <criterion comment="system32\winhttp.dll version less than 6.0.6000.16786" test_ref="oval:org.mitre.oval:tst:9981"/>
        </criteria>
        <criteria operator="AND" comment="winhttp.dll versin 6.0.6000.20971 or later on windows vista LDR (x86)(x64)">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criterion comment="system32\winhttp.dll version greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9442"/>
          <criterion comment="system32\winhttp.dll version less than 6.0.6000.20971" test_ref="oval:org.mitre.oval:tst:9594"/>
        </criteria>
        <criteria operator="AND" comment="winhttp.dll versin 6.0.6001.18178 or later on windows server 2008 sp1 GDR (x86)(x64)(ia64) and windows vista sp1 GDR (x86)(x64)">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="system32\winhttp.dll version greater than or equal 6.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9762"/>
          <criterion comment="system32\winhttp.dll version less than 6.0.6001.18178" test_ref="oval:org.mitre.oval:tst:9801"/>
        </criteria>
        <criteria operator="AND" comment="winhttp.dll versin 6.0.6001.22323 or later on windows server 2008 sp1 LDR (x86)(x64)(ia64) and windows vista sp1 GDR (x86)(x64)">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="system32\winhttp.dll version greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9825"/>
          <criterion comment="system32\winhttp.dll version less than 6.0.6001.22323" test_ref="oval:org.mitre.oval:tst:9119"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5314" version="3" class="vulnerability">
      <metadata>
        <title>DNS Spoofing Attack Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0087" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0087"/>
        <description>The DNS client in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, and Vista uses predictable DNS transaction IDs, which allows remote attackers to spoof DNS responses.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-04-08T16:04:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-04-11T14:11:47.310-04:00">DRAFT</status_change>
            <status_change date="2008-04-28T04:00:12.862-04:00">INTERIM</status_change>
            <status_change date="2008-05-19T04:00:10.681-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5314 - October Patch Tuesday" date="2011-10-14T15:53:00.263-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-10-14T15:54:24.501-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:04:08.262-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Dnsapi.dll version is less than 5.0.2195.7151" test_ref="oval:org.mitre.oval:tst:7583"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows XP SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="Dnsapi.dll version is less than 5.1.2600.3316" test_ref="oval:org.mitre.oval:tst:7425"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows XP x64 SP1/Server 2003 SP1 (x86)/(x64)/(ia-64)">
          <criteria operator="OR" comment="Windows XP x64 SP1/Server 2003 SP1 (x86)/(x64)/(ia-64)">
            <extend_definition comment="Microsoft Windows XP Professional x64 Edition SP1 is installed" definition_ref="oval:org.mitre.oval:def:720"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:4386"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
          </criteria>
          <criterion comment="Dnsapi.dll version is less than 5.2.3790.3092" test_ref="oval:org.mitre.oval:tst:7833"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows XP x64 SP2/Server 2003 SP2 (x86)/(x64)/(ia-64)">
          <criteria operator="OR" comment="Windows XP x64 SP2/Server 2003 SP2 (x86)/(x64)/(ia-64)">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="Dnsapi.dll version is less than 5.2.3790.4238" test_ref="oval:org.mitre.oval:tst:6999"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Vista (32-bit)/(x64)">
          <criteria operator="OR" comment="Windows Vista (32-bit)/(x64)">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criterion comment="Dnsapi.dll version is less than 6.0.6000.16615" test_ref="oval:org.mitre.oval:tst:7707"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if version of dnsapi.dll is greater than or equal to 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:43640"/>
              <criterion comment="Check if version of dnsapi.dll is less than 6.0.6000.20740" test_ref="oval:org.mitre.oval:tst:44173"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:531" version="3" class="vulnerability">
      <metadata>
        <title>IE v5.5,SP2 Function Pointer Drag and Drop Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1027" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1027"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CVE-2003-0823, aka the "Function Pointer Drag and Drop Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:46.100-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:22.035-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
          <criterion comment="the version of mshtml.dll is less than 5.50.4937.800" negate="false" test_ref="oval:org.mitre.oval:tst:2581"/>
          <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:530" version="5" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP4 Function Pointer Drag and Drop Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1027" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1027"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CVE-2003-0823, aka the "Function Pointer Drag and Drop Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:49:00.000-04:00" comment="modified wft-91 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed ste:2614: set datatype to version.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:54:00.319-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:59:45.361-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:43.759-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:45.989-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:21.956-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3813.800" negate="false" test_ref="oval:org.mitre.oval:tst:2582"/>
          <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5291" version="6" class="vulnerability">
      <metadata>
        <title>Request Header Cross-Domain Information Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 5.01</product>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1544" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1544"/>
        <description>The setRequestHeader method of the XMLHttpRequest object in Microsoft Internet Explorer 5.01, 6, and 7 does not block dangerous HTTP request headers when certain 8-bit character sequences are appended to a header name, which allows remote attackers to (1) conduct HTTP request splitting and HTTP request smuggling attacks via an incorrect Content-Length header, (2) access arbitrary virtual hosts via a modified Host header, (3) bypass referrer restrictions via an incorrect Referer header, and (4) bypass the same-origin policy and obtain sensitive information via a crafted request header.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-06-10T14:50:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-06-12T13:58:48.791-04:00">DRAFT</status_change>
            <status_change date="2008-06-30T04:00:12.751-04:00">INTERIM</status_change>
            <status_change date="2008-07-21T04:00:12.088-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5291 - Added LDR support" date="2011-10-25T14:12:00.742-04:00">
              <contributor organization="SecPod Technologies">Pooja Shetty</contributor>
            </modified>
            <status_change date="2011-10-25T14:18:09.930-04:00">INTERIM</status_change>
            <status_change date="2011-11-14T04:00:24.799-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5291 - extended definitions of OS are without SP checks" date="2014-07-28T17:42:00.658-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:44:55.332-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:05:57.006-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win 2K + IE5.01">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="Mshtml.dll version is less than 5.0.3864.1800" test_ref="oval:org.mitre.oval:tst:8007"/>
        </criteria>
        <criteria operator="AND" comment="Win 2K + IE6">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1611" test_ref="oval:org.mitre.oval:tst:8059"/>
        </criteria>
        <criteria operator="AND" comment="Win XP X86 and IE 6">
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3354" test_ref="oval:org.mitre.oval:tst:8055"/>
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
        </criteria>
        <criteria operator="AND" comment="Win XP / Win 2K3">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="Win XP / Win 2K3">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR / GDR">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16674" test_ref="oval:org.mitre.oval:tst:7361"/>
            <criteria operator="AND" comment="Check for GDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.20815" test_ref="oval:org.mitre.oval:tst:44283"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win XP X64 /Win 2K3 and IE6">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.3123" test_ref="oval:org.mitre.oval:tst:7949"/>
          <criteria operator="OR" comment="Win XP X64 /Win 2K3">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win XP X64/ Win 2K3 and IE 6">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4275" test_ref="oval:org.mitre.oval:tst:7988"/>
          <criteria operator="OR" comment="Win XP X64 /Win 2K3">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win Vista and IE 7">
          <extend_definition comment="Microsoft Windows Vista is installed" definition_ref="oval:org.mitre.oval:def:228"/>
          <criteria operator="OR" comment="Check for LDR / GDR">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16681" test_ref="oval:org.mitre.oval:tst:8012"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.20823" test_ref="oval:org.mitre.oval:tst:44003"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
        </criteria>
        <criteria operator="AND" comment="Win Vista / Win 2K8 and IE 7">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="Win Vista / Win 2K8">
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR / GDR">
            <criterion comment="Mshtml.dll version is less than 7.0.6001.18063" test_ref="oval:org.mitre.oval:tst:8066"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Mshtml.dll version is greater than or equal to 7.0.6001.22000" test_ref="oval:org.mitre.oval:tst:42152"/>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6001.22167" test_ref="oval:org.mitre.oval:tst:43645"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win XP X86 + IE6">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.2900.5583" test_ref="oval:org.mitre.oval:tst:43822"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:529" version="5" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP3 Function Pointer Drag and Drop Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1027" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1027"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CVE-2003-0823, aka the "Function Pointer Drag and Drop Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:50:00.000-04:00" comment="modified wft-90 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2824. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:48:00.494-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:52:24.763-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:43.533-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:50.510-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:21.885-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3015"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3526.800" negate="false" test_ref="oval:org.mitre.oval:tst:2589"/>
          <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5271" version="5" class="vulnerability">
      <metadata>
        <title>Windows Kernel TCP/IP/ICMP Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference ref_id="CVE-2007-0066" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0066" source="CVE"/>
        <description>The kernel in Microsoft Windows 2000 SP4, XP SP2, and Server 2003, when ICMP Router Discovery Protocol (RDP) is enabled, allows remote attackers to cause a denial of service via fragmented router advertisement ICMP packets that trigger an out-of-bounds read, aka "Windows Kernel TCP/IP/ICMP Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-01-08T14:23:12">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-02-18T04:00:07.173-05:00">INTERIM</status_change>
            <status_change date="2008-03-10T04:00:09.646-04:00">ACCEPTED</status_change>
            <modified comment="Changing deprecated obj:563 to obj:588" date="2010-01-12T15:19:00.407-05:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2010-01-12T15:21:54.947-05:00">INTERIM</status_change>
            <modified comment="Changing deprecated obj:563 to obj:588" date="2010-01-12T15:21:00.983-05:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </modified>
            <modified comment="Changing deprecated obj:563 to obj:588" date="2010-01-12T15:22:00.614-05:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </modified>
            <modified comment="Changing deprecated obj:563 to obj:588" date="2010-01-12T15:22:00.419-05:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </modified>
            <modified comment="Changing deprecated obj:563 to obj:588" date="2010-01-12T15:23:00.405-05:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2010-02-01T04:00:09.343-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5271 - Updated critiera and added LDR version check where appropriate" date="2011-10-25T14:25:00.196-04:00">
              <contributor organization="SecPod Technologies">Pooja Shetty</contributor>
            </modified>
            <status_change date="2011-10-25T14:27:01.001-04:00">INTERIM</status_change>
            <status_change date="2011-11-14T04:00:23.836-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win 2K SP4 and vulnerable version of file">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of tcpip.sys is less than 5.0.2195.7147" test_ref="oval:org.mitre.oval:tst:7823"/>
        </criteria>
        <criteria operator="AND" comment="Win XP X86 SP2 and vulnerable version">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="the version of tcpip.sys is less than 5.1.2600.3244" test_ref="oval:org.mitre.oval:tst:7452"/>
        </criteria>
        <criteria operator="AND" comment="Win XP X64 SP1 or Win 2K3 SP1 and vulnerable version">
          <criteria operator="OR" comment="Win XP 64  SP1 / Win 2k3 SP1">
            <extend_definition comment="Microsoft Windows XP Professional x64 Edition SP1 is installed" definition_ref="oval:org.mitre.oval:def:720"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:4386"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
          </criteria>
          <criterion comment="the version of tcpip.sys is less than 5.2.3790.3036" test_ref="oval:org.mitre.oval:tst:7779"/>
        </criteria>
        <criteria operator="AND" comment="Win XP X64 SP2 / Win 2K3 SP2 and vulnerable version of file">
          <criterion comment="the version of tcpip.sys is less than 5.2.3790.4179" test_ref="oval:org.mitre.oval:tst:7335"/>
          <criteria operator="OR" comment="Win 2K3 Sp2 / Win XP X64 SP2">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:527" version="5" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP2 Function Pointer Drag and Drop Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1027" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1027"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CVE-2003-0823, aka the "Function Pointer Drag and Drop Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:50:00.000-04:00" comment="modified wft-90 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2868. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:41:00.387-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:43:08.486-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:43.312-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:49.747-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:21.798-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3063"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3526.800" negate="false" test_ref="oval:org.mitre.oval:tst:2589"/>
          <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5266" version="5" class="vulnerability">
      <metadata>
        <title>HTML Objects Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2257" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2257"/>
        <description>Microsoft Internet Explorer 5.01, 6, and 7 accesses uninitialized memory in certain conditions, which allows remote attackers to cause a denial of service (crash) and execute arbitrary code via vectors related to a document object "appended in a specific order," aka "HTML Objects Memory Corruption Vulnerability" or "XHTML Rendering Memory Corruption Vulnerability," a different vulnerability than CVE-2008-2258.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-13T09:28:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-08-14T15:03:15.291-04:00">DRAFT</status_change>
            <status_change date="2008-09-01T04:00:52.868-04:00">INTERIM</status_change>
            <status_change date="2008-09-22T04:00:21.592-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:9018 - Included LDR support &amp; added new state to match correct version." date="2011-10-25T14:07:00.717-04:00">
              <contributor organization="SecPod Technologies">Pooja Shetty</contributor>
            </modified>
            <status_change date="2011-10-25T14:12:08.179-04:00">INTERIM</status_change>
            <status_change date="2011-11-14T04:00:22.988-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5266 - extended definitions of OS are without SP checks" date="2014-07-28T17:42:00.658-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:44:52.540-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:05:56.653-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win 2K + IE6 vulnerable version">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1613" test_ref="oval:org.mitre.oval:tst:8781"/>
        </criteria>
        <criteria operator="AND" comment="Win 2K + IE 5.01">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="Mshtml.dll version is less than 5.0.3866.2000" test_ref="oval:org.mitre.oval:tst:8949"/>
        </criteria>
        <criteria operator="AND" comment="Win XP + IE 6">
          <extend_definition comment="Microsoft Windows XP is installed" definition_ref="oval:org.mitre.oval:def:105"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3395" test_ref="oval:org.mitre.oval:tst:8921"/>
        </criteria>
        <criteria operator="AND" comment="Win XP + IE 6">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5626" test_ref="oval:org.mitre.oval:tst:9128"/>
        </criteria>
        <criteria operator="AND" comment="Win XP /  Win 2K3 + IE 7">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="Win XP / Win 2K3">
            <extend_definition comment="Microsoft Windows XP is installed" definition_ref="oval:org.mitre.oval:def:105"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR / GDR">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16705" test_ref="oval:org.mitre.oval:tst:9018"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Check if the version mshtml.dll is less than 7.0.6000.20861" test_ref="oval:org.mitre.oval:tst:44137"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 2K3 / Win XP X64 and IE 6">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.3167" test_ref="oval:org.mitre.oval:tst:8958"/>
          <criteria operator="OR" comment="Win 2K3 / Win XP X64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win XP X64 / Win 2K3">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4324" test_ref="oval:org.mitre.oval:tst:8988"/>
          <criteria operator="OR" comment="Win 2K3 / Win XP X64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win Vista and IE7">
          <extend_definition comment="Microsoft Windows Vista is installed" definition_ref="oval:org.mitre.oval:def:228"/>
          <criteria operator="OR" comment="Check for LDR and GDR">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16711" test_ref="oval:org.mitre.oval:tst:8163"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.20868" test_ref="oval:org.mitre.oval:tst:44258"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
        </criteria>
        <criteria operator="AND" comment="Win Vista / Win 2K8 and IE7">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="Win Vista/ Win 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR /GDR">
            <criterion comment="Mshtml.dll version is less than 7.0.6001.18099" test_ref="oval:org.mitre.oval:tst:9108"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Mshtml.dll version is greater than or equal to 7.0.6001.22000" test_ref="oval:org.mitre.oval:tst:42152"/>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6001.22212" test_ref="oval:org.mitre.oval:tst:44416"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:525" version="2" class="vulnerability">
      <metadata>
        <title>Microsoft Data Access Components 2.5 Broadcast Response Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Data Access Components 2.5</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0903" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0903"/>
        <description>Buffer overflow in a component of Microsoft Data Access Components (MDAC) 2.5 through 2.8 allows remote attackers to execute arbitrary code via a malformed UDP response to a broadcast request.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.717-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-10-25T16:57:27.859-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:01:18.770-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Microsoft Data Access Components 2.5 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2576"/>
        <criterion comment="the version of odbcbcp.dll is less than 3.70.11.46" negate="false" test_ref="oval:org.mitre.oval:tst:2575"/>
        <criterion comment="the version of sqlsrv32.dll is less than 3.70.11.46" negate="false" test_ref="oval:org.mitre.oval:tst:2574"/>
        <criterion comment="the patch q832483 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2573"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5248" version="2" class="vulnerability">
      <metadata>
        <title>SMB Validation Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4835" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4835"/>
        <description>SMB in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to execute arbitrary code via malformed values of unspecified "fields inside the SMB packets" in an NT Trans2 request, related to "insufficiently validating the buffer size," aka "SMB Validation Remote Code Execution Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-01-13T13:07:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <modified comment="Changed the comparison operator for GDR/LDR lower bound file version checks" date="2009-01-26T08:52:29.700-05:00">
              <contributor organization="National Institute of Standards and Technology">Timothy Harrison</contributor>
            </modified>
            <status_change date="2009-01-20T17:42:25.490-05:00">DRAFT</status_change>
            <status_change date="2009-02-16T04:00:11.612-05:00">INTERIM</status_change>
            <status_change date="2009-03-09T04:00:07.729-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Srv.sys version is less than 5.0.2195.7222" test_ref="oval:org.mitre.oval:tst:9419"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="Srv.sys version is less than 5.1.2600.3491" test_ref="oval:org.mitre.oval:tst:9449"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Srv.sys version is less than 5.1.2600.5725" test_ref="oval:org.mitre.oval:tst:9588"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="Srv.sys version is less than 5.2.3790.3260" test_ref="oval:org.mitre.oval:tst:9297"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <criterion comment="Srv.sys version is less than 5.2.3790.4425" test_ref="oval:org.mitre.oval:tst:9603"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:4386"/>
            <extend_definition comment="Microsoft Windows XP x64 Edition SP1 is installed" definition_ref="oval:org.mitre.oval:def:720"/>
          </criteria>
          <criterion comment="Srv.sys version is less than 5.2.3790.3260" test_ref="oval:org.mitre.oval:tst:9297"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          </criteria>
          <criterion comment="Srv.sys version is less than 5.2.3790.4425" test_ref="oval:org.mitre.oval:tst:9603"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9543"/>
          <criterion comment="Srv.sys version is less than 6.0.6000.16789" test_ref="oval:org.mitre.oval:tst:9450"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:8674"/>
          <criterion comment="Srv.sys version is less than 6.0.6000.20976" test_ref="oval:org.mitre.oval:tst:8697"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9601"/>
          <criterion comment="Srv.sys version is less than 6.0.6001.18185" test_ref="oval:org.mitre.oval:tst:9369"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9666"/>
          <criterion comment="Srv.sys version is less than 6.0.6001.22331" test_ref="oval:org.mitre.oval:tst:8713"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6000.16000" test_ref="oval:org.mitre.oval:tst:9543"/>
          <criterion comment="Srv.sys version is less than 6.0.6000.16789" test_ref="oval:org.mitre.oval:tst:9450"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:8674"/>
          <criterion comment="Srv.sys version is less than 6.0.6000.20976" test_ref="oval:org.mitre.oval:tst:8697"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6001.18000" test_ref="oval:org.mitre.oval:tst:9601"/>
          <criterion comment="Srv.sys version is less than 6.0.6001.18185" test_ref="oval:org.mitre.oval:tst:9369"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criterion comment="Srv.sys version is greater than or equal to 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:9666"/>
          <criterion comment="Srv.sys version is less than 6.0.6001.22331" test_ref="oval:org.mitre.oval:tst:8713"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5236" version="11" class="vulnerability">
      <metadata>
        <title>MJPEG Decoder Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>DirectX</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0011" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0011"/>
        <description>Microsoft DirectX 8.1 through 9.0c, and DirectX on Microsoft XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008, does not properly perform MJPEG error checking, which allows remote attackers to execute arbitrary code via a crafted MJPEG stream in a (1) AVI or (2) ASF file, aka the "MJPEG Decoder Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-06-10T14:50:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-06-12T13:58:51.032-04:00">DRAFT</status_change>
            <status_change date="2008-06-30T04:00:11.306-04:00">INTERIM</status_change>
            <modified comment="Updated to reflect Microsoft's updating of MS07-064 and MS08-033 which now declares DirectX 9.0a, 9.0b, and 9.0c vulnerable." date="2008-07-18T10:12:00.799-04:00">
              <contributor organization="Secure Elements, Inc.">Jeff Ito</contributor>
            </modified>
            <status_change date="2008-08-04T04:00:13.344-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5236 - added LDR, Win Vista/2008 SP1 &amp; 64-bit support" date="2011-11-03T15:21:00.340-04:00">
              <contributor organization="SecPod Technologies">Prashanth A.</contributor>
            </modified>
            <status_change date="2011-11-03T15:24:59.149-04:00">INTERIM</status_change>
            <status_change date="2011-11-21T04:13:10.604-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5236 - OVAL definition 5236 was using an incorrect operator for one of the criteria." date="2011-11-29T11:11:00.831-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2011-11-29T11:12:25.804-05:00">INTERIM</status_change>
            <status_change date="2011-12-19T04:00:47.377-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5236 - Correcting incorrect references to 64-bit Itanium XP." date="2012-08-23T17:47:00.168-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-08-23T17:52:41.835-04:00">INTERIM</status_change>
            <status_change date="2012-09-10T04:00:57.539-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:3502 - obj/ste updates to conform to authoring style guide" date="2013-03-26T09:53:00.500-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-03-26T09:55:58.393-04:00">INTERIM</status_change>
            <status_change date="2013-04-15T04:00:24.277-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5236 - extended definitions of OS are without SP checks" date="2014-07-28T17:42:00.658-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:44:53.710-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:05:56.279-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="DirectX 8.1/7.0 on Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <criterion comment="the version of Quartz.dll is less than 6.3.1.891" test_ref="oval:org.mitre.oval:tst:7847"/>
          <criterion comment="DirectX 8.1 Installed" test_ref="oval:org.mitre.oval:tst:6805"/>
        </criteria>
        <criteria operator="AND" comment="DirectX 9.0 on Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <criterion comment="DirectX 9.0x Installed" test_ref="oval:org.mitre.oval:tst:601"/>
          <criterion comment="the version of Quartz.dll is less than 6.5.1.909" test_ref="oval:org.mitre.oval:tst:7882"/>
        </criteria>
        <criteria operator="AND" comment="DirectX 9.0 on Win XP">
          <extend_definition comment="Microsoft Windows XP is installed" definition_ref="oval:org.mitre.oval:def:105"/>
          <criterion comment="DirectX 9.0x Installed" test_ref="oval:org.mitre.oval:tst:601"/>
          <criterion comment="the version of Quartz.dll is less than 6.5.2600.3367" test_ref="oval:org.mitre.oval:tst:7926"/>
        </criteria>
        <criteria operator="AND" comment="DirectX 9.0 on Win XP">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="DirectX 9.0x Installed" test_ref="oval:org.mitre.oval:tst:601"/>
          <criterion comment="the version of Quartz.dll is less than 6.5.2600.5596" test_ref="oval:org.mitre.oval:tst:7725"/>
        </criteria>
        <criteria operator="AND" comment="DirectX 9.0 on 2003 and XP">
          <criteria operator="OR" comment="Check for Vulnerable Windows 2003 and Windows XP">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <criterion comment="DirectX 9.0x Installed" test_ref="oval:org.mitre.oval:tst:601"/>
          <criterion comment="the version of Quartz.dll is less than 6.5.3790.3130" test_ref="oval:org.mitre.oval:tst:7765"/>
        </criteria>
        <criteria operator="AND" comment="DirectX 9.0 on 2003 and XP">
          <criteria operator="OR" comment="Check for Vulnerable Windows 2003 and Windows XP">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
          <criterion comment="DirectX 9.0x Installed" test_ref="oval:org.mitre.oval:tst:601"/>
          <criterion comment="the version of Quartz.dll is less than 6.5.3790.4283" test_ref="oval:org.mitre.oval:tst:8024"/>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable Windows Vista(x86)/(x64) and Quartz.dll version">
          <criteria operator="OR" comment="Check for vulnerable Windows Vista(x86)/(x64)">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criterion comment="the version of Quartz.dll is less than 6.6.6000.16681" test_ref="oval:org.mitre.oval:tst:8069"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="the version of Quartz.dll is greater than or equal 6.6.6000.20000" test_ref="oval:org.mitre.oval:tst:21068"/>
              <criterion comment="Check if version of  Quartz.dll is less than 6.6.6000.20823" test_ref="oval:org.mitre.oval:tst:74932"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for Vulnerable Windows Vista(x86)/(x64)/Windows 2008(x86)/(x64)/(ia-64) and Quartz.dll version">
          <criteria operator="OR" comment="Check for Vulnerable Windows Vista(x86)/(x64)/Windows 2008(x86)/(x64)/(ia-64)">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criterion comment="the version of Quartz.dll is less than 6.6.6001.18063" test_ref="oval:org.mitre.oval:tst:8092"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="the version of Quartz.dll is greater than or equal 6.6.6001.22000" test_ref="oval:org.mitre.oval:tst:20940"/>
              <criterion comment="Check if version of Quartz.dll is less than 6.6.6001.22167" test_ref="oval:org.mitre.oval:tst:75065"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5231" version="1" class="vulnerability">
      <metadata>
        <title>Parameter Validation Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4258" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4258"/>
        <description>Microsoft Internet Explorer 5.01 SP4 and 6 SP1 does not properly validate parameters during calls to navigation methods, which allows remote attackers to execute arbitrary code via a crafted HTML document that triggers memory corruption, aka "Parameter Validation Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-12-09T13:31:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-12-12T16:42:51.615-05:00">DRAFT</status_change>
            <status_change date="2008-12-29T04:00:18.065-05:00">INTERIM</status_change>
            <status_change date="2009-01-19T04:00:06.589-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1617" test_ref="oval:org.mitre.oval:tst:9607"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="Mshtml.dll version is less than 5.0.3870.1500" test_ref="oval:org.mitre.oval:tst:9553"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:520" version="4" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP3 Zone Restrictions Bypass via XML Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0817" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0817"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions and read arbitrary files via an XML object.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for Windows 2000 sp3 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp3 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2824. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:48:00.494-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:52:28.658-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:42.856-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:48.358-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:21.669-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3015"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3523.1700" negate="false" test_ref="oval:org.mitre.oval:tst:2693"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5181" version="10" class="vulnerability">
      <metadata>
        <title>Windows Active Directory Denial of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0088" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0088"/>
        <description>Unspecified vulnerability in Active Directory on Microsoft Windows 2000 and Windows Server 2003, and Active Directory Application Mode (ADAM) on XP and Server 2003, allows remote attackers to cause a denial of service (hang and restart) via a crafted LDAP request.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-02-14T10:00:19">
              <contributor organization="Secure Elements, Inc.">Jeff Ito</contributor>
            </submitted>
            <status_change date="2008-02-14T14:55:53.429-05:00">DRAFT</status_change>
            <status_change date="2008-03-03T04:00:09.970-05:00">INTERIM</status_change>
            <status_change date="2008-03-24T04:00:40.071-04:00">ACCEPTED</status_change>
            <modified comment="Added test for checking if system is used as AD" date="2009-09-05T13:00:00.035-04:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2009-09-14T04:00:16.865-04:00">INTERIM</status_change>
            <status_change date="2009-10-05T04:00:03.941-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:5285 - obj:5285 is pointing to windows\system32 directory. But, adamdsa.dll file by default will be in windows\ADAM directory" date="2011-07-14T10:24:00.833-04:00">
              <contributor organization="SecPod Technologies">Sharath S</contributor>
            </modified>
            <status_change date="2011-07-14T10:26:45.857-04:00">INTERIM</status_change>
            <status_change date="2011-08-01T04:00:55.559-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5181 - def:5181 updated to add support for Win2003 IA-64 SP1 and SP2." date="2011-10-28T21:07:00.303-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2011-10-28T21:22:25.318-04:00">INTERIM</status_change>
            <status_change date="2011-11-14T04:00:21.835-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5181 - modified vulnerabilities which check the version of file adamdsa.dll" date="2013-12-18T16:36:00.218-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-18T16:44:40.277-05:00">INTERIM</status_change>
            <status_change date="2014-01-06T04:00:47.788-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:89195 - bulletin MS14-016, for the month of Mar 2014." date="2014-03-18T14:40:00.553-04:00">
              <contributor organization="SecPod Technologies">Pooja Shetty</contributor>
            </modified>
            <status_change date="2014-03-18T14:42:04.397-04:00">INTERIM</status_change>
            <status_change date="2014-04-07T04:06:54.852-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="NTDS Service is installed" test_ref="oval:org.mitre.oval:tst:42615"/>
          <criterion comment="ntdsa.dll version is less than 5.0.2195.7147" test_ref="oval:org.mitre.oval:tst:7660"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows XP SP2 (x86)/(x64)">
          <criteria operator="OR" comment="Windows XP SP2 (x86)/(x64)">
            <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          </criteria>
          <criterion comment="Check if ADAM service is installed" test_ref="oval:org.mitre.oval:tst:89195"/>
          <criterion comment="adamdsa.dll version is less than 1.1.3790.4188" test_ref="oval:org.mitre.oval:tst:7403"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows XP x64 SP1">
          <extend_definition comment="Microsoft Windows XP Professional x64 Edition SP1 is installed" definition_ref="oval:org.mitre.oval:def:720"/>
          <criterion comment="Check if ADAM service is installed" test_ref="oval:org.mitre.oval:tst:89195"/>
          <criterion comment="adamdsa.dll version is less than 1.1.3790.3043" test_ref="oval:org.mitre.oval:tst:7838"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Server 2003 SP1 (x86)/(x64)">
          <criteria operator="OR" comment="Windows Server 2003 SP1 (x86)/(x64)">
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <criteria operator="OR" comment="Vulnerable Active directory or ADAM">
            <criteria operator="AND">
              <criterion comment="NTDS Service is installed" test_ref="oval:org.mitre.oval:tst:42615"/>
              <criterion comment="ntdsa.dll version is less than 5.2.3790.3043" test_ref="oval:org.mitre.oval:tst:7380"/>
            </criteria>
            <criteria operator="AND">
              <criterion comment="Check if ADAM service is installed" test_ref="oval:org.mitre.oval:tst:89195"/>
              <criterion comment="adamdsa.dll version is less than 1.1.3790.3043" test_ref="oval:org.mitre.oval:tst:7838"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Server 2003 SP2 (x86)/(x64)">
          <criteria operator="OR" comment="Windows Server 2003 SP2 (x86)/(x64)">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
          </criteria>
          <criteria operator="OR" comment="Vulnerable Active Directory or ADAM">
            <criteria operator="AND">
              <criterion comment="NTDS Service is installed" test_ref="oval:org.mitre.oval:tst:42615"/>
              <criterion comment="ntdsa.dll version is less than 5.2.3790.4188" test_ref="oval:org.mitre.oval:tst:7566"/>
            </criteria>
            <criteria operator="AND">
              <criterion comment="Check if ADAM service is installed" test_ref="oval:org.mitre.oval:tst:89195"/>
              <criterion comment="adamdsa.dll version is less than 1.1.3790.4188" test_ref="oval:org.mitre.oval:tst:7403"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows Server 2003 SP1 ia-64">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
          <criterion comment="NTDS Service is installed" test_ref="oval:org.mitre.oval:tst:42615"/>
          <criterion comment="ntdsa.dll version is less than 5.2.3790.3043" test_ref="oval:org.mitre.oval:tst:7380"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Server 2003 SP2 ia-64">
          <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          <criterion comment="the system is being used as AD - DomainRole is 4 or 5" test_ref="oval:org.mitre.oval:tst:10696"/>
          <criterion comment="NTDS Service is installed" test_ref="oval:org.mitre.oval:tst:42615"/>
          <criterion comment="ntdsa.dll version is less than 5.2.3790.4188" test_ref="oval:org.mitre.oval:tst:7566"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5150" version="6" class="vulnerability">
      <metadata>
        <title>IE v5.01, SP4 SSL Cached Content Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0845" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0845"/>
        <description>Internet Explorer 5.01, 5.5, and 6 does not properly cache SSL content, which allows remote attackers to obtain information or spoof content via a web site with the same host name as the target web site, whose content is cached and reused when the user visits the target web site.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-01-20T02:31:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-06-23T12:49:00.000-04:00" comment="modified obj:490 - Chagned the pattern match operation to equals since there was no need for a regular expression.">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-06-23T11:35:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:29.549-04:00">ACCEPTED</status_change>
            <modified comment="Fixed ste:2614: set datatype to version.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:54:00.319-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:59:42.093-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:42.366-05:00">ACCEPTED</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.853-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-10-25T16:53:30.687-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:01:18.516-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:47.802-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:21.476-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3534.2800" negate="false" test_ref="oval:org.mitre.oval:tst:519"/>
          <criterion comment="the patch kb834707-ie501sp4 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:518"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Users not saving encrypted pages to disk  (DisableCachingOfSSLPages)" negate="false" test_ref="oval:org.mitre.oval:tst:588"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:515" version="4" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP2 Bitmap Integer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0566" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0566"/>
        <description>Integer overflow in imgbmp.cxx for Windows 2000 allows remote attackers to execute arbitrary code via a BMP image with a large bfOffBits value.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-08-02T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2868. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:41:00.387-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:43:09.802-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:42.124-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:42.989-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:21.423-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 5.01 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3063"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3532.300" negate="false" test_ref="oval:org.mitre.oval:tst:2803"/>
        <criterion comment="the patch kb832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2802"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:513" version="5" class="vulnerability">
      <metadata>
        <title>IE v6.0,SP1 Improper URL Canonicalization Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1025" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1025"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the "Improper URL Canonicalization Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:52:00.000-04:00" comment="modified wft-94 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:45:59.589-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:41.965-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:43.645-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:21.331-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2800.1400" negate="false" test_ref="oval:org.mitre.oval:tst:2579"/>
        <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:511" version="3" class="vulnerability">
      <metadata>
        <title>IE v5.5,SP2 Improper URL Canonicalization Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1025" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1025"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the "Improper URL Canonicalization Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:43.785-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:21.232-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
        <criterion comment="the version of mshtml.dll is less than 5.50.4937.800" negate="false" test_ref="oval:org.mitre.oval:tst:2581"/>
        <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:510" version="5" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP4 Improper URL Canonicalization Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1025" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1025"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the "Improper URL Canonicalization Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:49:00.000-04:00" comment="modified wft-91 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed ste:2614: set datatype to version.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:54:00.319-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:59:38.610-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:41.812-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:43.964-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:21.164-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3813.800" negate="false" test_ref="oval:org.mitre.oval:tst:2582"/>
        <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:509" version="5" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP4 Malformed GIF Image Double-free Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1048" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1048"/>
        <description>Double free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-08-02T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:21:00.000-04:00" comment="modified wft-279 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed ste:2614: set datatype to version.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:54:00.319-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:59:43.183-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:41.656-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:44.540-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:21.111-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Software section">
        <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" test_ref="oval:org.mitre.oval:tst:2794"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3819.300" test_ref="oval:org.mitre.oval:tst:2793"/>
        <criterion negate="true" comment="the patch kb832894 is installed (Installed Components key)" test_ref="oval:org.mitre.oval:tst:2802"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:508" version="4" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP2 Zone Restrictions Bypass via XML Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0817" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0817"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions and read arbitrary files via an XML object.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for Windows 2000 sp2 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp2 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2868. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:41:00.387-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:43:09.567-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:41.485-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:44.466-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:21.028-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3063"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3523.1700" negate="false" test_ref="oval:org.mitre.oval:tst:2693"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:502" version="10" class="vulnerability">
      <metadata>
        <title>HTML Rendering Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference ref_id="CVE-2006-3637" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3637" source="CVE"/>
        <description>Microsoft Internet Explorer 5.01 SP4 and 6 does not properly handle various HTML layout component combinations, which allows user-assisted remote attackers to execute arbitrary code via a crafted HTML file that leads to memory corruption, aka "HTML Rendering Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:29.304-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:43.220-04:00">ACCEPTED</status_change>
            <modified comment="Added an anchor to the regex used to check for Internet Explorer 6." date="2007-01-11T20:38:00.950-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-01-11T20:49:17.868-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:40.863-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:2185 - Anchored regular expression" date="2011-02-22T12:51:00.261-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:52:34.965-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:00:51.908-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:45.597-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:20.866-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:136 - modified comments" date="2014-02-28T15:13:00.247-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-28T15:16:20.993-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:20.677-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:502 - Addressed validation errors and duplicate extended definitions" date="2015-07-13T20:21:00.869-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:25:24.209-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:01:55.388-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Server 2003-Gold">
          <extend_definition comment="Microsoft Windows Server 2003 (x86) Gold is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.554" test_ref="oval:org.mitre.oval:tst:136"/>
        </criteria>
        <criteria comment="XP,SP1 (64-bit) and Server 2003, SP1">
          <criteria operator="OR" comment="Windows XP (64-bit,SP1) or Server 2003 (SP1) is installed">
            <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2759" test_ref="oval:org.mitre.oval:tst:175"/>
        </criteria>
        <criteria comment="IE 6 on Windows XP,SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.2963" test_ref="oval:org.mitre.oval:tst:95"/>
        </criteria>
        <criteria comment="IE 6 on Windows 2000 or XP,SP1 (32-bit)">
          <criteria operator="OR" comment="Win2K,SP4 or XP,SP1 (32-bit) is installed">
            <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
            <extend_definition comment="Microsoft Windows XP SP1 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1561" test_ref="oval:org.mitre.oval:tst:56"/>
        </criteria>
        <criteria comment="IE 5.01,SP4 on Win2k,SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3842.3000" test_ref="oval:org.mitre.oval:tst:106"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:50" version="3" class="vulnerability">
      <metadata>
        <title>IE v5.01 GetObject File Retrieval</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0023" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0023"/>
        <description>Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to read arbitrary files via malformed requests to the GetObject function, which bypass some of GetObject's security checks.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified comment="Corrected ste:2875 set datatype to version on version element. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-12T20:46:00.631-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-12T20:47:58.750-05:00">INTERIM</status_change>
            <modified comment="Corrected ste:2873. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-12T20:52:00.978-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <modified comment="Corrected ste:2874. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-12T21:00:00.301-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <modified comment="Corrected ste:2871. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-12T21:03:00.158-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <modified comment="Corrected ste:2872. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-12T21:06:00.183-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <modified comment="Corrected ste:2870. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:36:00.896-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <modified comment="Corrected ste:2869. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:39:00.994-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <modified comment="Corrected ste:2868. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:41:00.387-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-02-20T13:40:40.531-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:37.537-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:20.775-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Internet Explorer 5.01 Installed">
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3070"/>
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3069"/>
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3068"/>
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3067"/>
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3066"/>
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3065"/>
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3064"/>
          <criterion comment="Internet Explorer 5.01 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3063"/>
        </criteria>
        <criterion comment="the version of mshtml.dll is less than 5.0.3502.4856" negate="false" test_ref="oval:org.mitre.oval:tst:3012"/>
        <criterion comment="the patch q316059 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3121"/>
        <criterion comment="the patch q319282 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3120"/>
        <criterion comment="the patch q321232 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3119"/>
        <criterion comment="the patch q323759 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3118"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5" version="10" class="vulnerability">
      <metadata>
        <title>CSS Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference ref_id="CVE-2006-3451" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3451" source="CVE"/>
        <description>Microsoft Internet Explorer 5 SP4 and 6 do not properly garbage collect when "multiple imports are used on a styleSheets collection" to construct a chain of Cascading Style Sheets (CSS), which allows remote attackers to execute arbitrary code via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:28.875-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:42.731-04:00">ACCEPTED</status_change>
            <modified comment="Added an anchor to the regex used to check for Internet Explorer 6." date="2007-01-11T20:38:00.950-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-01-11T20:49:16.187-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:40.257-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:2185 - Anchored regular expression" date="2011-02-22T12:51:00.261-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:52:35.415-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:00:51.359-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:44.031-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:20.672-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:136 - modified comments" date="2014-02-28T15:13:00.247-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-28T15:16:21.312-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:20.441-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5 - Addressed validation errors and duplicate extended definitions" date="2015-07-13T20:21:00.869-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:25:24.607-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:01:55.201-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Server 2003-Gold">
          <extend_definition comment="Microsoft Windows Server 2003 (x86) Gold is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.554" test_ref="oval:org.mitre.oval:tst:136"/>
        </criteria>
        <criteria comment="XP,SP1 (64-bit) and Server 2003, SP1">
          <criteria operator="OR" comment="Windows XP (64-bit,SP1) or Server 2003 (SP1) is installed">
            <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2759" test_ref="oval:org.mitre.oval:tst:175"/>
        </criteria>
        <criteria comment="IE 6 on Windows XP,SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.2963" test_ref="oval:org.mitre.oval:tst:95"/>
        </criteria>
        <criteria comment="IE 6 on Windows 2000 or XP,SP1 (32-bit)">
          <criteria operator="OR" comment="Win2K,SP4 or XP,SP1 (32-bit) is installed">
            <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
            <extend_definition comment="Microsoft Windows XP SP1 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1561" test_ref="oval:org.mitre.oval:tst:56"/>
        </criteria>
        <criteria comment="IE 5.01,SP4 on Win2k,SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3842.3000" test_ref="oval:org.mitre.oval:tst:106"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4988" version="6" class="vulnerability">
      <metadata>
        <title>Windows 2000 Message Queuing Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Message Queuing</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0059" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0059"/>
        <description>Buffer overflow in the Message Queuing component of Microsoft Windows 2000 and Windows XP SP1 allows remote attackers to execute arbitrary code via a crafted message.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-02T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2005-05-04T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-06-17T12:00:00.000-04:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2005-07-27T10:37:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected and tightened regular expression in ste:2610" date="2010-12-02T11:46:00.307-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-12-02T11:47:28.283-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:01:01.473-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:57.456-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:03:08.282-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 (sp4 or earlier) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 5 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2790"/>
        </criteria>
        <criterion comment="the version of mqrt.dll is less than 5.0.0.799" negate="false" test_ref="oval:org.mitre.oval:tst:285"/>
        <criterion comment="the patch KB892944 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:328"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4987" version="5" class="vulnerability">
      <metadata>
        <title>Microsoft .NET Framework v1.0 Security Bypass</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft .NET Framework</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0847" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0847"/>
        <description>The Microsoft .NET forms authentication capability for ASP.NET allows remote attackers to bypass authentication for .aspx files in restricted directories via a request containing a (1) "\" (backslash) or (2) "%5C" (encoded backslash), aka "Path Validation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-31T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-04-12T08:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Set xsi:nil=&quot;true&quot; on name sub-element of obj:267.  Implemented by Harvey Rubinovitz." date="2007-01-08T16:36:00.431-05:00">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2007-01-08T16:40:23.526-05:00">INTERIM</status_change>
            <modified comment="Updated metadata: changed affected product to .NET Framework (was MDAC 2.7), and added Microsoft Windows 2000 as affected platform." date="2007-01-08T17:19:00.528-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <modified comment="Fixed obj:264: Removed repeated string in key.  Implemented by Matthew Wojcik." date="2007-01-23T13:34:00.065-05:00">
              <contributor organization="GFI Software">Daniel Tarnu</contributor>
            </modified>
            <status_change date="2007-02-20T13:40:39.846-05:00">ACCEPTED</status_change>
            <modified comment="Corrected obj:263 to use variable that constructs the path to the .net 1.1 directory." date="2007-07-18T13:42:00.929-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-07-18T13:44:10.000-04:00">INTERIM</status_change>
            <status_change date="2007-08-02T14:47:16.146-04:00">ACCEPTED</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.569-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-10-25T16:57:00.767-04:00">INTERIM</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.540-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-11-13T12:01:17.728-05:00">ACCEPTED</status_change>
            <modified comment="Removed the leading &quot;\&quot; from the key." date="2008-02-04T10:03:00.376-05:00">
              <contributor organization="Hewlett-Packard">Jeff Cheng</contributor>
            </modified>
            <status_change date="2008-02-04T10:08:27.718-05:00">INTERIM</status_change>
            <status_change date="2008-02-25T04:00:09.634-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Software section">
        <criterion comment="Is the Microsoft .NET Framework 1.0 installed" test_ref="oval:org.mitre.oval:tst:292"/>
        <criteria operator="OR" comment="A vulnerable version of Microsoft .NET Framework v1.0 is installed.">
          <criteria operator="AND" comment="A vulnerable version of Microsoft .NET Framework v1.0 (SP 2) is installed.">
            <criterion negate="true" comment="Is the KB886905 patch installed for Microsoft .NET Framework v1.0 sp 2?" test_ref="oval:org.mitre.oval:tst:291"/>
            <criterion comment="the version of System.web.dll is less than 1.0.3705.556" test_ref="oval:org.mitre.oval:tst:290"/>
            <criterion comment="Is Service Pack 2 for Microsoft .NET Framework 1.0 installed" test_ref="oval:org.mitre.oval:tst:289"/>
          </criteria>
          <criteria operator="AND" comment="A vulnerable version of Microsoft .NET Framework v1.0 (SP 3) is installed.">
            <criterion comment="Is Service Pack 3 for Microsoft .NET Framework 1.0 installed" test_ref="oval:org.mitre.oval:tst:288"/>
            <criterion comment="the version of System.web.dll is less than 1.0.3705.6021" test_ref="oval:org.mitre.oval:tst:287"/>
            <criterion negate="true" comment="Is the KB886906 patch installed for Microsoft .NET Framework v1.0 sp 3?" test_ref="oval:org.mitre.oval:tst:286"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4985" version="4" class="vulnerability">
      <metadata>
        <title>DHTML Object Memory Corruption Vulnerability (IE5.01,SP4)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0553" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0553"/>
        <description>Race condition in the memory management routines in the DHTML object processor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail, aka "DHTML Object Memory Corruption Vulnerability".</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-05-11T05:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed ste:2614: set datatype to version.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:54:00.319-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:59:45.189-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:39.635-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:49.935-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:20.603-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3826.2400" negate="false" test_ref="oval:org.mitre.oval:tst:567"/>
          <criterion comment="the patch kb890923 is installed (Win2K SP4  Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:566"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:495" version="3" class="vulnerability">
      <metadata>
        <title>IE v5.5 Encoded Characters Information Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1186" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1186"/>
        <description>Internet Explorer 5.01 through 6.0 does not properly perform security checks on certain encoded characters within a URL, which allows a remote attacker to steal potentially sensitive information from a user by redirecting the user to another site that has that information, aka "Encoded Characters Information Disclosure."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-27T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:35.369-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:20.548-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Internet Explorer 5.5 Installed">
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3078"/>
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3077"/>
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3076"/>
          <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
        </criteria>
        <criterion comment="the version of mshtml.dll is less than 5.50.4922.900" negate="false" test_ref="oval:org.mitre.oval:tst:2786"/>
        <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
        <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
        <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4947" version="5" class="vulnerability">
      <metadata>
        <title>IE5.01,SP4 Channel Definition Format Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0056" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0056"/>
        <description>Internet Explorer 5.01, 5.5, and 6 does not properly validate certain URLs in Channel Definition Format (CDF) files, which allows remote attackers to obtain sensitive information or execute arbitrary code, aka the "Channel Definition Format (CDF) Cross Domain Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-03-23T08:09:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-13T12:15:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-05-04T12:33:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed test to check kb867282.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed ste:2614: set datatype to version.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:54:00.319-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:59:45.906-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:39.413-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:41.451-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:20.486-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3825.700" negate="false" test_ref="oval:org.mitre.oval:tst:994"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:494" version="6" class="vulnerability">
      <metadata>
        <title>MS Windows RPC DCOM DoS-based Privilege Escalation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Remote Procedure Call (RPC)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0605" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0605"/>
        <description>The RPC DCOM interface in Windows 2000 SP3 and SP4 allows remote attackers to cause a denial of service (crash), and local attackers to use the DoS to hijack the epmapper pipe to gain privileges, via certain messages to the __RemoteGetClassObject interface that cause a NULL pointer to be passed to the PerformScmStage function.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-12-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Multiple corrections and update to POSIX compatibility for ste:2884" date="2010-11-29T16:14:00.692-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-11-29T16:14:40.118-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:01:01.214-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:16.426-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:03:07.115-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="the version of rpcrt4.dll is less than 5.0.2195.6802" negate="false" test_ref="oval:org.mitre.oval:tst:2914"/>
          <criterion comment="the patch kb824146 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:3082"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="DCOM is enabled on systems with SP3 or later">
            <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3079"/>
            <criterion comment="DCOM is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2913"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4927" version="5" class="vulnerability">
      <metadata>
        <title>MSN Messenger GIF Size Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>MSN Messenger</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0562" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0562"/>
        <description>GIF file validation error in MSN Messenger 6.2 allows remote attackers in a user's contact list to execute arbitrary code via a GIF image with an improper height and width.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-04-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-04-20T12:13:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-05-11T05:41:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-11-24T12:00:00.000-04:00" comment="Added wrt-620 to see if MSN Messenger 6.2 is installed.  Changed wrt-431 to check 'DisplayVersion' rather than 'MSN Messenger 6.2'.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <modified date="2005-12-20T07:05:00.000-04:00" comment="Added wrt-431.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-04T08:04:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:1436" date="2007-04-23T12:05:00.002-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:31:50.312-04:00">INTERIM</status_change>
            <status_change date="2007-05-09T16:11:06.297-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:1436 - vulnerabilities for VMware and inventories for VMware Workstation, VMware View and VMware Player." date="2013-06-21T12:00:00.019-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-06-21T12:13:31.098-04:00">INTERIM</status_change>
            <status_change date="2013-07-08T04:02:56.930-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="MSN Messenger 6.2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2520"/>
        <criterion comment="MSN Messenger 6.2.0208 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:294"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:492" version="5" class="vulnerability">
      <metadata>
        <title>Buffer Overrun in Server Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference ref_id="CVE-2006-3439" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3439" source="CVE"/>
        <description>Buffer overflow in the Server Service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers, including anonymous users, to execute arbitrary code via a crafted RPC message, a different vulnerability than CVE-2006-1314.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:28.555-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:42.347-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:492 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:05:05.698-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:35.426-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:492 - modified comments" date="2014-02-28T15:13:00.247-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-28T15:16:14.305-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:20.273-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win2K,SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="The version of netapi32.dll is less than 5.0.2195.7105." test_ref="oval:org.mitre.oval:tst:13"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP1">
          <extend_definition comment="Microsoft Windows XP SP1 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          <criterion comment="The version of netapi32.dll is less than 5.1.2600.1874" test_ref="oval:org.mitre.oval:tst:147"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="The version of netapi32.dll is less than 5.1.2600.2952." test_ref="oval:org.mitre.oval:tst:101"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP1 (64-bit)">
          <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="The version of netapi32.dll is less than 5.2.3790.2747." test_ref="oval:org.mitre.oval:tst:126"/>
        </criteria>
        <criteria operator="AND" comment="S03-Gold">
          <extend_definition comment="Microsoft Windows Server 2003 (x86) Gold is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="The version of netapi32.dll is less than 5.2.3790.559." test_ref="oval:org.mitre.oval:tst:176"/>
        </criteria>
        <criteria operator="AND" comment="S03,SP1">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="The version of netapi32.dll is less than 5.2.3790.2747." test_ref="oval:org.mitre.oval:tst:126"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4910" version="10" class="vulnerability">
      <metadata>
        <title>Windows Active Directory Denial of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1445" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1445"/>
        <description>Active Directory on Microsoft Windows 2000 Server SP4, XP Professional SP2 and SP3, Server 2003 SP1 and SP2, and Server 2008 allows remote authenticated users to cause a denial of service (system hang or reboot) via a crafted LDAP request.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-06-10T16:00:00">
              <contributor organization="Secure Elements, Inc.">Jeff Ito</contributor>
            </submitted>
            <status_change date="2008-06-12T13:58:53.030-04:00">DRAFT</status_change>
            <status_change date="2008-06-30T04:00:06.328-04:00">INTERIM</status_change>
            <status_change date="2008-07-21T04:00:10.785-04:00">ACCEPTED</status_change>
            <modified comment="Added test for checking if system is used as AD" date="2009-09-05T12:00:00.035-04:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2009-09-14T04:00:16.292-04:00">INTERIM</status_change>
            <status_change date="2009-10-05T04:00:03.031-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:5285 - obj:5285 is pointing to windows\system32 directory. But, adamdsa.dll file by default will be in windows\ADAM directory" date="2011-07-14T10:24:00.833-04:00">
              <contributor organization="SecPod Technologies">Sharath S</contributor>
            </modified>
            <status_change date="2011-07-14T10:26:44.081-04:00">INTERIM</status_change>
            <status_change date="2011-08-01T04:00:54.884-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:4910 - Added Win 2003 IA-64 SP1 and SP2 criteria &amp; LDR for Win2008" date="2011-11-14T13:18:00.866-05:00">
              <contributor organization="SecPod Technologies">Pradeep R B</contributor>
            </modified>
            <status_change date="2011-11-14T13:20:15.003-05:00">INTERIM</status_change>
            <status_change date="2011-12-05T04:00:24.505-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:4910 - modified vulnerabilities which check the version of file adamdsa.dll" date="2013-12-18T16:36:00.218-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-18T16:44:40.069-05:00">INTERIM</status_change>
            <status_change date="2014-01-06T04:00:47.545-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:89195 - bulletin MS14-016, for the month of Mar 2014." date="2014-03-18T14:40:00.553-04:00">
              <contributor organization="SecPod Technologies">Pooja Shetty</contributor>
            </modified>
            <status_change date="2014-03-18T14:42:03.863-04:00">INTERIM</status_change>
            <status_change date="2014-04-07T04:06:54.649-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="NTDS Service is installed" test_ref="oval:org.mitre.oval:tst:42615"/>
          <criterion comment="ntdsa.dll version is less than 5.0.2195.7155" test_ref="oval:org.mitre.oval:tst:7906"/>
          <criterion comment="the system is being used as AD - DomainRole is 4 or 5" test_ref="oval:org.mitre.oval:tst:10696"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Server 2003 SP1 (x86)/(x64)">
          <criteria operator="OR" comment="Windows Server 2003 SP1 (x86)/(x64)">
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <criteria operator="OR" comment="Vulnerable Active directory or ADAM">
            <criteria operator="AND" comment="Vulnerable ADAM">
              <criterion comment="Check if ADAM service is installed" test_ref="oval:org.mitre.oval:tst:89195"/>
              <criterion comment="adamdsa.dll version is less than 1.1.3790.3129" test_ref="oval:org.mitre.oval:tst:8089"/>
            </criteria>
            <criteria operator="AND" comment="Vulnerable Active Directory">
              <criterion comment="NTDS Service is installed" test_ref="oval:org.mitre.oval:tst:42615"/>
              <criterion comment="ntdsa.dll version is less than 5.2.3790.3122" test_ref="oval:org.mitre.oval:tst:7398"/>
              <criterion comment="the system is being used as AD - DomainRole is 4 or 5" test_ref="oval:org.mitre.oval:tst:10696"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Server 2003 SP2 (x86)/(x64)">
          <criteria operator="OR" comment="Windows Server 2003 SP2 (x86)/(x64)">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
          </criteria>
          <criteria operator="OR" comment="Vulnerable Active Directory or ADAM">
            <criteria operator="AND" comment="Vulnerable ADAM">
              <criterion comment="Check if ADAM service is installed" test_ref="oval:org.mitre.oval:tst:89195"/>
              <criterion comment="adamdsa.dll version is less than 1.1.3790.4281" test_ref="oval:org.mitre.oval:tst:8048"/>
            </criteria>
            <criteria operator="AND" comment="Vulnerable Active Directory">
              <criterion comment="NTDS Service is installed" test_ref="oval:org.mitre.oval:tst:42615"/>
              <criterion comment="ntdsa.dll version is less than 5.2.3790.4274" test_ref="oval:org.mitre.oval:tst:7451"/>
              <criterion comment="the system is being used as AD - DomainRole is 4 or 5" test_ref="oval:org.mitre.oval:tst:10696"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows XP SP2/SP3">
          <criteria operator="OR" comment="Windows XP SP2/SP3">
            <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
            <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          </criteria>
          <criterion comment="Check if ADAM service is installed" test_ref="oval:org.mitre.oval:tst:89195"/>
          <criterion comment="adamdsa.dll version is less than 1.1.3790.4276" test_ref="oval:org.mitre.oval:tst:7989"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows XP x64 SP1">
          <extend_definition comment="Microsoft Windows XP Professional x64 Edition SP1 is installed" definition_ref="oval:org.mitre.oval:def:720"/>
          <criterion comment="Check if ADAM service is installed" test_ref="oval:org.mitre.oval:tst:89195"/>
          <criterion comment="adamdsa.dll version is less than 1.1.3790.3129" test_ref="oval:org.mitre.oval:tst:8089"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows XP x64 SP2">
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          <criterion comment="Check if ADAM service is installed" test_ref="oval:org.mitre.oval:tst:89195"/>
          <criterion comment="adamdsa.dll version is less than 1.1.3790.4281" test_ref="oval:org.mitre.oval:tst:8048"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Server 2008 (32-bit)/(x64)">
          <criteria operator="OR" comment="Windows Server 2008 (32-bit)/(x64)">
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criterion comment="ntdsai.dll version is less than 6.0.6001.18072" test_ref="oval:org.mitre.oval:tst:8018"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="ntdsai.dll is greater than or equal 6.0.6001.22000" test_ref="oval:org.mitre.oval:tst:10907"/>
              <criterion comment="Check if version of ntdsai.dll is less than 6.0.6001.22179" test_ref="oval:org.mitre.oval:tst:76801"/>
            </criteria>
            <criterion comment="the system is being used as AD - DomainRole is 4 or 5" test_ref="oval:org.mitre.oval:tst:10696"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Server 2003 SP1 ia-64">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
          <criterion comment="NTDS Service is installed" test_ref="oval:org.mitre.oval:tst:42615"/>
          <criterion comment="ntdsa.dll version is less than 5.2.3790.3122" test_ref="oval:org.mitre.oval:tst:7398"/>
          <criterion comment="the system is being used as AD - DomainRole is 4 or 5" test_ref="oval:org.mitre.oval:tst:10696"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Server 2003 SP2 ia-64">
          <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          <criterion comment="NTDS Service is installed" test_ref="oval:org.mitre.oval:tst:42615"/>
          <criterion comment="ntdsa.dll version is less than 5.2.3790.4274" test_ref="oval:org.mitre.oval:tst:7451"/>
          <criterion comment="the system is being used as AD - DomainRole is 4 or 5" test_ref="oval:org.mitre.oval:tst:10696"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:491" version="5" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP3 Improper URL Canonicalization Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1025" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1025"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the "Improper URL Canonicalization Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:50:00.000-04:00" comment="modified wft-90 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2824. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:48:00.494-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:52:25.906-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:39.201-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:35.607-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:20.430-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3015"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3526.800" negate="false" test_ref="oval:org.mitre.oval:tst:2589"/>
        <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4904" version="11" class="vulnerability">
      <metadata>
        <title>Argument Handling Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference ref_id="CVE-2008-0078" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0078" source="CVE"/>
        <description>Unspecified vulnerability in an ActiveX control (dxtmsft.dll) in Microsoft Internet Explorer 5.01, 6 SP1 and SP2, and 7 allows remote attackers to execute arbitrary code via a crafted image, aka "Argument Handling Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-02-13T10:19:01">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-02-13T16:35:14.541-05:00">DRAFT</status_change>
            <modified date="2008-03-02T04:44:54" comment="Added file check to ensure a full installation.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <modified comment="Fixed typo" date="2008-03-11T09:58:00.328-04:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2008-03-31T04:00:06.215-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:4904 - Added LDR support and removed IE 5.01 criteria where appropriate" date="2011-10-25T14:22:00.696-04:00">
              <contributor organization="SecPod Technologies">Pooja Shetty</contributor>
            </modified>
            <status_change date="2011-10-25T14:25:17.623-04:00">INTERIM</status_change>
            <status_change date="2011-11-14T04:00:20.262-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:4904 - Correcting incorrect references to 64-bit Itanium XP." date="2012-08-23T17:47:00.168-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-08-23T17:52:12.628-04:00">INTERIM</status_change>
            <status_change date="2012-09-10T04:00:56.710-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:34.959-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:20.283-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:4904 - extended definitions of OS are without SP checks" date="2014-07-28T18:04:00.247-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:06:29.634-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:4904 - Updated to remove SP checks." date="2014-08-07T14:51:00.976-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-25T04:01:50.108-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 5.01,SP4 on Win2k">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3860.1000" test_ref="oval:org.mitre.oval:tst:7584"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win 2k">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1607" test_ref="oval:org.mitre.oval:tst:7696"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win XP">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2900.3268" test_ref="oval:org.mitre.oval:tst:7834"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win 2003 or Win XP X64">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.3064" test_ref="oval:org.mitre.oval:tst:7573"/>
          <criteria operator="OR" comment="Win XP X64/ Win 2K3">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win 2003 / Win XP X64">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.4210" test_ref="oval:org.mitre.oval:tst:7792"/>
          <criteria operator="OR" comment="Win XP X64 / Win 2K3">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 7 on Win 2003 platforms">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="Win XP / Win 2K3 and IE 7">
            <extend_definition comment="Microsoft Windows XP is installed" definition_ref="oval:org.mitre.oval:def:105"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR / GDR">
            <criterion comment="the version of mshtml.dll is less than 7.0.6000.16608" test_ref="oval:org.mitre.oval:tst:7827"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.20733" test_ref="oval:org.mitre.oval:tst:44297"/>
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 7 on Win Vista platforms">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="Windows Vista 32/ 64 bit">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR / GDR">
            <criterion comment="the version of mshtml.dll is less than 7.0.6000.16609" test_ref="oval:org.mitre.oval:tst:7396"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.20734" test_ref="oval:org.mitre.oval:tst:44122"/>
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1867" version="10" class="inventory">
      <metadata>
        <title>Microsoft Windows Server 2003 for Itanium is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_server_2003:::itanium"/>
        <description>A version of Microsoft Windows Server 2003 for Itanium is
          installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-04-10T16:31:02">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-04-25T19:52:20.536-04:00">INTERIM</status_change>
            <status_change date="2007-05-23T15:05:33.881-04:00">ACCEPTED</status_change>
            <modified comment="Changed the CPE reference" date="2008-04-04T11:17:00.945-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2008-04-04T11:24:23.967-04:00">INTERIM</status_change>
            <status_change date="2008-04-21T04:00:14.656-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1867 - Updated Windows 2003 Server CPE names." date="2011-03-29T13:48:00.699-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-03-29T13:51:33.404-04:00">INTERIM</status_change>
            <status_change date="2011-04-18T04:00:34.881-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1867 - Modifications vary from minor OVAL title/description changes to suggesting an alternative CPE name to use." date="2011-09-28T11:29:00.976-04:00">
              <contributor organization="The MITRE Corporation">David Rothenberg</contributor>
            </modified>
            <status_change date="2011-09-28T11:33:43.469-04:00">INTERIM</status_change>
            <status_change date="2011-10-17T04:00:13.370-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1867 - Un-deprecated incorrect partially deprecation of two Definitions." date="2011-12-09T17:21:00.310-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2011-12-09T17:23:42.622-05:00">INTERIM</status_change>
            <status_change date="2011-12-26T04:02:48.929-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1867 - Multiple updates to several Windows OVAL entities. Includes CPE, title, and description updates. Fixed incorrectly referenced criteria. Added new criteria, fixed criteria checks, and improved criteria comments for several definitions." date="2012-11-02T20:20:00.882-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-11-02T20:24:45.532-04:00">INTERIM</status_change>
            <status_change date="2012-11-19T04:00:33.002-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Windows Server 2003 is installed" definition_ref="oval:org.mitre.oval:def:128"/>
        <criterion comment="a version of Windows for the ia64 architecture is installed" test_ref="oval:org.mitre.oval:tst:2747"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:490" version="5" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP2 Improper URL Canonicalization Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1025" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1025"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the "Improper URL Canonicalization Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:50:00.000-04:00" comment="modified wft-90 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2868. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:41:00.387-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:43:10.547-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:38.999-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:35.748-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:20.186-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 5.01 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3063"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3526.800" negate="false" test_ref="oval:org.mitre.oval:tst:2589"/>
        <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:49" version="3" class="vulnerability">
      <metadata>
        <title>IE v5.01 Improper Cross Domain Security Validation with Dialog Box</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1326" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1326"/>
        <description>Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model to run malicious script or arbitrary programs via dialog boxes, aka "Improper Cross Domain Security Validation with dialog box."</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified comment="Corrected ste:2875 set datatype to version on version element. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-12T20:46:00.631-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-12T20:47:59.459-05:00">INTERIM</status_change>
            <modified comment="Corrected ste:2873. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-12T20:52:00.978-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <modified comment="Corrected ste:2874. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-12T21:00:00.301-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <modified comment="Corrected ste:2871. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-12T21:03:00.158-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <modified comment="Corrected ste:2872. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-12T21:06:00.183-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <modified comment="Corrected ste:2870. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:36:00.896-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <modified comment="Corrected ste:2869. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:39:00.994-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <modified comment="Corrected ste:2868. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:41:00.387-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <modified comment="Corrected ste:2824. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:48:00.494-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-02-20T13:40:38.675-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:35.184-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:20.061-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Internet Explorer 5.01 Installed">
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3070"/>
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3069"/>
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3068"/>
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3067"/>
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3066"/>
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3065"/>
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3064"/>
          <criterion comment="Internet Explorer 5.01 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3063"/>
          <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3015"/>
        </criteria>
        <criterion comment="File %windir%\system32\mshtml.dll version is less than 5.0.3513.900" negate="false" test_ref="oval:org.mitre.oval:tst:3014"/>
        <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3013"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:489" version="2" class="vulnerability">
      <metadata>
        <title>Unchecked Buffer in SQLXML ISAPI Extension for Microsoft Data Access Components 2.7</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft SQL Server 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0186" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0186"/>
        <description>Buffer overflow in the SQLXML ISAPI extension of Microsoft SQL Server 2000 allows remote attackers to execute arbitrary code via data queries with a long content-type parameter, aka "Unchecked Buffer in SQLXML ISAPI Extension."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-09-15T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <modified date="2004-09-16T12:00:00.000-04:00" comment="Input of initial submission.">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </modified>
            <status_change date="2004-09-22T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-10-06T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-10-20T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-04-08T12:00:00.000-04:00" comment="modified wft-492 - wft-492 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-11T08:48:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="SQL Server 2000 installed" negate="false" test_ref="oval:org.mitre.oval:tst:2591"/>
        <criterion comment="Microsoft Data Access Components 2.7 (RTM) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2590"/>
        <criterion comment="the version of sqlisapi.dll is less than 2000.80.309.0" negate="false" test_ref="oval:org.mitre.oval:tst:2594"/>
        <criterion comment="the version of sqlservr.exe is less than 2000.80.760.0" negate="false" test_ref="oval:org.mitre.oval:tst:2593"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4874" version="4" class="vulnerability">
      <metadata>
        <title>DHTML Object Memory Corruption Vulnerability (IE5.01,SP3)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0553" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0553"/>
        <description>Race condition in the memory management routines in the DHTML object processor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail, aka "DHTML Object Memory Corruption Vulnerability".</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-05-11T05:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2824. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:48:00.494-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:52:29.286-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:38.317-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:46.855-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:19.990-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3015"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3539.2400" negate="false" test_ref="oval:org.mitre.oval:tst:1083"/>
          <criterion comment="the patch kb890923  is installed (Win2K SP3  Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:1082"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4864" version="7" class="vulnerability">
      <metadata>
        <title>IE5.01,SP4 Drag-and-Drop Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0053" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0053"/>
        <description>Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the "Drag-and-Drop Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-03-23T08:09:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-13T12:15:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-05-04T12:33:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed test to check kb867282.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed ste:2614: set datatype to version.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:54:00.319-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:59:38.772-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:38.010-05:00">ACCEPTED</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.795-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-10-25T16:47:49.181-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:01:17.465-05:00">ACCEPTED</status_change>
            <modified comment="Fix for regular expression" date="2010-01-13T14:40:00.667-05:00">
              <contributor organization="The MITRE Corporation">Dan Haynes</contributor>
            </modified>
            <status_change date="2010-01-13T14:41:05.301-05:00">INTERIM</status_change>
            <status_change date="2010-02-01T04:00:08.134-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:58.707-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:19.891-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3825.700" negate="false" test_ref="oval:org.mitre.oval:tst:994"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="Check for Drag&amp;Drop enabled and the patch kb834707(wildcard*)  missing">
            <criterion comment="Drag-and-Drop disabled when set to 3" negate="true" test_ref="oval:org.mitre.oval:tst:1316"/>
            <criterion comment="the patch kb834707(wildcard*) is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:977"/>
          </criteria>
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:484" version="2" class="vulnerability">
      <metadata>
        <title>Unchecked Buffer in SQLXML ISAPI Extension for Microsoft Data Access Components 2.6</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft SQL Server 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0186" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0186"/>
        <description>Buffer overflow in the SQLXML ISAPI extension of Microsoft SQL Server 2000 allows remote attackers to execute arbitrary code via data queries with a long content-type parameter, aka "Unchecked Buffer in SQLXML ISAPI Extension."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-09-15T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <modified date="2004-09-16T12:00:00.000-04:00" comment="filling out initial submission.">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </modified>
            <modified date="2004-09-16T10:31:00.000-04:00" comment="Added service pack 3 test">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </modified>
            <status_change date="2004-09-22T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-10-06T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-10-20T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-04-08T12:00:00.000-04:00" comment="modified wft-492 - wft-492 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-11T08:48:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="SQL Server 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2977"/>
        <criterion comment="Microsoft Data Access Components 2.6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2717"/>
        <criterion comment="the version of sqlisapi.dll is less than 2000.80.309.0" negate="false" test_ref="oval:org.mitre.oval:tst:2594"/>
        <criterion comment="the version of sqlservr.exe is less than 2000.80.760.0" negate="false" test_ref="oval:org.mitre.oval:tst:2593"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4832" version="6" class="vulnerability">
      <metadata>
        <title>Windows 2000 Object Management Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0550" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0550"/>
        <description>Buffer overflow in Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to cause a denial of service (i.e., system crash) via a malformed request, aka "Object Management Vulnerability".</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-02T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2005-05-04T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-06-17T12:00:00.000-04:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2005-07-27T10:37:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected and tightened regular expression in ste:2610" date="2010-12-02T11:46:00.307-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-12-02T11:47:26.587-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:01:00.827-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:46:18.332-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:03:06.379-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 (sp4 or earlier) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 5 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2790"/>
        </criteria>
        <criterion comment="The version of Ntoskrnl.exe is less than 5.0.2195.7035" negate="false" test_ref="oval:org.mitre.oval:tst:2358"/>
        <criterion comment="the patch KB890859 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2737"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:483" version="8" class="vulnerability">
      <metadata>
        <title>IIS Server Side Include Web Pages Buffer Overrun</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0224" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0224"/>
        <description>Buffer overflow in ssinc.dll for Microsoft Internet Information Services (IIS) 5.0 allows local users to execute arbitrary code via a web page with a Server Side Include (SSI) directive with a long filename, aka "Server Side Include Web Pages Buffer Overrun."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-03-07T12:00:00.000-04:00" comment="modified wrt-222 - changed pattern match">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-03-09T07:55:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-29T07:59:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected to use a forward slash as the separator in the key." date="2007-05-07T15:59:00.964-04:00">
              <contributor organization="Secure Elements, Inc.">Glenn Strickland</contributor>
            </modified>
            <status_change date="2007-05-07T16:05:38.842-04:00">INTERIM</status_change>
            <status_change date="2007-05-23T15:05:47.405-04:00">ACCEPTED</status_change>
            <modified comment="Multiple corrections and update to POSIX compatibility for ste:2878" date="2010-11-29T16:13:00.904-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-11-29T16:14:05.462-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:01:00.470-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:05.866-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:03:05.925-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
          <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
          <criterion comment="File %windir%\system32\inetsrv\ssinc.dll version is less than 5.0.2195.6624" negate="false" test_ref="oval:org.mitre.oval:tst:2595"/>
          <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
          <criterion comment="SP4 or later Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3073"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="SmartHTML interpreter is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2705"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4791" version="5" class="vulnerability">
      <metadata>
        <title>Win2k Large Window Size TCP RST Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0230" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0230"/>
        <description>TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use long-lived connections, such as BGP.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-04-22T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-04-27T12:06:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-11-06T04:13:00.000-04:00" comment="Replaced reference to var:200 with reference to var:201 in obj:588 since tcpip.sys is located in \system32\drivers and not \system32.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:53:58.351-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:44:31.925-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:03:04.644-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="Win2K/XP/2003 service pack 4 (or earlier) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1247"/>
        <criterion comment="the version of Tcpip.sys is less than 5.0.2195.7035" negate="false" test_ref="oval:org.mitre.oval:tst:1012"/>
        <criterion comment="the patch KB893066 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2353"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:478" version="3" class="vulnerability">
      <metadata>
        <title>MS Internet Security and Acceleration Server H.323 Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Security and Acceleration Server 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0819" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0819"/>
        <description>Buffer overflow in the H.323 filter of Microsoft Internet Security and Acceleration Server 2000 allows remote attackers to execute arbitrary code in the Microsoft Firewall Service via certain H.323 traffic, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed obj:1477: filename was '323ftlr.dll' due to conversion error.  Now 'h323ftlr.dll'." date="2007-01-22T16:48:00.041-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-01-22T16:49:43.158-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:37.595-05:00">ACCEPTED</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.657-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-10-25T16:50:14.165-04:00">INTERIM</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.722-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.575-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.264-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-11-13T12:01:16.914-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="ISA Server 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2935"/>
          <criterion comment="the version of h32fltr.dll is less than 3.0.1200.291" negate="false" test_ref="oval:org.mitre.oval:tst:2599"/>
          <criterion comment="the patch q816458 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2598"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="H.323 filter is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2597"/>
          <criterion comment="Microsoft Firewall Service is not disabled" negate="false" test_ref="oval:org.mitre.oval:tst:2596"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:477" version="1" class="vulnerability">
      <metadata>
        <title>MS Exchange / OWA NTLM Authentication Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Exchange Server</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0904" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0904"/>
        <description>Microsoft Exchange 2003 and Outlook Web Access (OWA), when configured to use NTLM authentication, does not properly reuse HTTP connections, which can cause OWA users to view mailboxes of other users when Kerberos has been disabled as an authentication method for IIS 6.0, e.g. when SharePoint Services 2.0 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1480 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-28T12:00:00.000-04:00">INTERIM</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.093-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.038-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Software section">
          <criterion comment="Exchange Server 2003 (gold edition) is installed" test_ref="oval:org.mitre.oval:tst:2760"/>
          <criterion comment="the version of exprox.dll is less than 6.5.6980.57" test_ref="oval:org.mitre.oval:tst:2605"/>
          <criterion negate="true" comment="the patch KB832759 is installed" test_ref="oval:org.mitre.oval:tst:2604"/>
        </criteria>
        <criteria operator="AND" comment="Configuration section">
          <criterion comment="this is a front-end server providing Outlook Web Access" test_ref="oval:org.mitre.oval:tst:2603"/>
          <criterion comment="the back-end server is Exchange Server 2003 running on Windows 2003" test_ref="oval:org.mitre.oval:tst:2602"/>
          <criterion negate="true" comment="HTTP connection reuse is disabled" test_ref="oval:org.mitre.oval:tst:2601"/>
          <criterion comment="Kerberos is disabled on the virtual server that hosts OWA on the Exchange Server 2003 back-end server" test_ref="oval:org.mitre.oval:tst:2600"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4741" version="8" class="vulnerability">
      <metadata>
        <title>HyperTerminal Session File Vulnerability (Windows 2000)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>HyperTerminal</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0568" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0568"/>
        <description>HyperTerminal application for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the length of a value that is saved in a session file, which allows remote attackers to execute arbitrary code via a malicious HyperTerminal session file (.ht), web site, or Telnet URL contained in an e-mail message, triggering a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-12-21T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-01-18T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-03-02T12:00:00.000-04:00" comment="modified wft-200 - access DLL via HKLM">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2005-03-23T08:09:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed obj:282: Removed blank before the word Filelist in the Key.  Implemented by Harvey Rubinovitz." date="2007-01-22T00:21:00.615-05:00">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2007-01-22T00:23:15.729-05:00">INTERIM</status_change>
            <modified comment="Fixed obj:282: changed Hive from HKEY_CLASSES_ROOT to HKEY_LOCAL_MACHINE.  Implemented by Harvey Rubinovitz." date="2007-01-22T01:09:00.941-05:00">
              <contributor organization="GFI Software">Daniel Tarnu</contributor>
            </modified>
            <status_change date="2007-02-20T13:40:37.079-05:00">ACCEPTED</status_change>
            <modified comment="Updated ste:741 to use regex pattern match instead of hardcoded path" date="2009-10-19T16:07:00.879-04:00">
              <contributor organization="The MITRE Corporation">Mike Lah</contributor>
            </modified>
            <status_change date="2009-10-19T16:09:06.580-04:00">INTERIM</status_change>
            <modified comment="Fixed registry key reference in obj:625" date="2009-10-19T16:09:00.553-04:00">
              <contributor organization="The MITRE Corporation">Mike Lah</contributor>
            </modified>
            <status_change date="2009-11-09T04:00:17.014-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:46:28.083-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:03:03.904-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:741 - obj/ste updates to conform to authoring style guide" date="2013-03-26T09:53:00.500-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-03-26T09:56:23.166-04:00">INTERIM</status_change>
            <status_change date="2013-04-15T04:00:23.463-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or earlier) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1247"/>
          <criterion comment="the version of hypertrm.dll is less than 5.0.2195.7000" negate="false" test_ref="oval:org.mitre.oval:tst:307"/>
          <criterion comment="the patch Windows2000-KB873339-x86-ENU.EXE is installed" negate="true" test_ref="oval:org.mitre.oval:tst:306"/>
        </criteria>
        <criteria comment="Configuration section" operator="OR">
          <criterion comment="If key present hyperterminal will automatically open session files" negate="false" test_ref="oval:org.mitre.oval:tst:827"/>
          <criterion comment="If the Hyperterminal client is registered as the default telnet client" negate="false" test_ref="oval:org.mitre.oval:tst:826"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:474" version="3" class="vulnerability">
      <metadata>
        <title>Windows 2000 Plug and Play Buffer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1983" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1983"/>
        <description>Stack-based buffer overflow in the Plug and Play (PnP) service for Microsoft Windows 2000 and Windows XP Service Pack 1 allows remote attackers to execute arbitrary code via a crafted packet, and local users to gain privileges via a malicious application, as exploited by the Zotob (aka Mytob) worm.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:40:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:48.172-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:55.755-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:474 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:04:39.612-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:34.741-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Windows 2000 is installed" test_ref="oval:org.mitre.oval:tst:3381"/>
        <criterion comment="the version of umpnpmgr.dll is less than 5.0.2195.7057" test_ref="oval:org.mitre.oval:tst:3723"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4710" version="6" class="vulnerability">
      <metadata>
        <title>MSHTA Code Execution Vulnerability (Windows 2000)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows Shell</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0063" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0063"/>
        <description>The document processing application used by the Windows Shell in Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by modifying the CLSID stored in a file so that it is processed by HTML Application Host (MSHTA), as demonstrated using a Microsoft Word document.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-04T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-05-04T10:01:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-06-17T12:00:00.000-04:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2005-07-27T10:37:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected and tightened regular expression in ste:2610" date="2010-12-02T11:46:00.307-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-12-02T11:47:26.982-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:59.829-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:46:34.211-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:03:03.562-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows 2000 (sp4 or earlier) is installed">
            <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
            <criterion comment="Win2K/XP/2003 service pack 5 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2790"/>
          </criteria>
          <criterion comment="the version of shell32.dll is less than 5.0.3900.7032" negate="false" test_ref="oval:org.mitre.oval:tst:313"/>
          <criterion comment="the patch  KB893086 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:312"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment=".hta applications are enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2915"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:471" version="4" class="vulnerability">
      <metadata>
        <title>IE v5.01 Encoded Characters Information Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1186" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1186"/>
        <description>Internet Explorer 5.01 through 6.0 does not properly perform security checks on certain encoded characters within a URL, which allows a remote attacker to steal potentially sensitive information from a user by redirecting the user to another site that has that information, aka "Encoded Characters Information Disclosure."</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-29T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2875 set datatype to version on version element. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-12T20:46:00.631-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-12T20:47:58.969-05:00">INTERIM</status_change>
            <modified comment="Corrected ste:2873. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-12T20:52:00.978-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <modified comment="Corrected ste:2874. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-12T21:00:00.301-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <modified comment="Corrected ste:2871. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-12T21:03:00.158-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <modified comment="Corrected ste:2872. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-12T21:06:00.183-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <modified comment="Corrected ste:2870. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:36:00.896-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <modified comment="Corrected ste:2869. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:39:00.994-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <modified comment="Corrected ste:2868. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:41:00.387-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-02-20T13:40:36.706-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:55.487-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:19.599-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Internet Explorer 5.01 Installed">
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3070"/>
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3069"/>
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3068"/>
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3067"/>
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3066"/>
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3065"/>
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3064"/>
          <criterion comment="Internet Explorer 5.01 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3063"/>
        </criteria>
        <criterion comment="File %windir%\system32\mshtml.dll version is less than 5.0.3510.1100" negate="false" test_ref="oval:org.mitre.oval:tst:2606"/>
        <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
        <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
        <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4702" version="4" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP4 Similar Method Name Redirection Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0727" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0727"/>
        <description>Microsoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows remote web servers to bypass zone restrictions and execute arbitrary code in the local computer zone by redirecting a function to another function with the same name, as demonstrated by SimilarMethodNameRedir, aka the "Similar Method Name Redirection Cross Domain Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-19T07:27:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed ste:2614: set datatype to version.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:54:00.319-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:59:41.060-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:36.423-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:35.439-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:19.508-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3534.2800" negate="false" test_ref="oval:org.mitre.oval:tst:519"/>
          <criterion comment="the patch kb834707-ie501sp4 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:518"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:468" version="4" class="vulnerability">
      <metadata>
        <title>ISA Server NetBIOS Packet Filter Bypass Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Security and Acceleration Server 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1216" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1216"/>
        <description>Microsoft ISA Server 2000 allows remote attackers to connect to services utilizing the NetBIOS protocol via a NetBIOS connection with an ISA Server that uses the NetBIOS (all) predefined packet filter.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-23T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-06-29T04:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-07-27T04:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T04:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-19T04:00:00.000-04:00" comment="modified wft-81 - Removed extra trailing \\ on registry component.">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:468 - Corrected capitalization and extra spacing errors in product names" date="2011-04-08T16:13:00.153-04:00">
              <contributor organization="AIST">Akihito Nakamura</contributor>
            </modified>
            <status_change date="2011-04-08T16:17:39.508-04:00">INTERIM</status_change>
            <status_change date="2011-04-25T04:00:20.293-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="ISA Server 2000 SP2 (or earlier) is installed" test_ref="oval:org.mitre.oval:tst:2611"/>
        <criterion comment="the version of w3proxy.exe is less than 3.0.1200.430" test_ref="oval:org.mitre.oval:tst:2610"/>
        <criterion negate="true" comment="the patch KB899753 is installed" test_ref="oval:org.mitre.oval:tst:2609"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4671" version="8" class="vulnerability">
      <metadata>
        <title>LoadImage Cursor and Icon Format Handling Vulnerability (Windows 2000)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Cursor and Icon Formatting</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1049" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1049"/>
        <description>Integer overflow in the LoadImage API of the USER32 Lib for Microsoft Windows allows remote attackers to execute arbitrary code via a .bmp, .cur, .ico or .ani file with a large image size field, which leads to a buffer overflow, aka the "Cursor and Icon Format Handling Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-20T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-17T12:00:00.000-04:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2005-06-22T12:35:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">ACCEPTED</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.059-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-10-25T16:50:28.008-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:01:16.241-05:00">ACCEPTED</status_change>
            <modified comment="Corrected and tightened regular expression in ste:2610" date="2010-12-02T11:46:00.307-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-12-02T11:47:27.075-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:59.470-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:44:35.229-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:03:02.877-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 (sp4 or earlier) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 5 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2790"/>
        </criteria>
        <criterion comment="the version of user32.dll is less than 5.0.2195.7017" negate="false" test_ref="oval:org.mitre.oval:tst:446"/>
        <criterion comment="the patch kb891711 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2807"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:467" version="6" class="vulnerability">
      <metadata>
        <title>Windows 2000 Unknown Vector SMB Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Small Business Server 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1206" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1206"/>
        <description>Buffer overflow in the Server Message Block (SMB) functionality for Microsoft Windows 2000, XP SP1 and SP2, and Server 2003 and SP1 allows remote attackers to execute arbitrary code via unknown vectors, aka the "Server Message Block Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-22T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2005-06-22T12:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected and tightened regular expression in ste:2610" date="2010-12-02T11:46:00.307-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-12-02T11:47:27.514-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:59.180-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:44:51.570-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:03:02.582-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the patch KB896422 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2743"/>
        <criterion comment="the version of srv.sys is less than 5.0.2195.7044" negate="false" test_ref="oval:org.mitre.oval:tst:2612"/>
        <criterion comment="Win2K/XP/2003 service pack 5 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2790"/>
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:463" version="7" class="vulnerability">
      <metadata>
        <title>Windows 2000 HTML Help Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>HTML Help Facility</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1208" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1208"/>
        <description>Integer overflow in Microsoft Windows 98, 2000, XP SP2 and earlier, and Server 2003 SP1 and earlier allows remote attackers to execute arbitrary code via a crafted compiled Help (.CHM) file with a large size field that triggers a heap-based buffer overflow, as demonstrated using a "ms-its:" URL in Internet Explorer.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2005-06-22T12:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Updated tst:2668 to refer to the correct a new object that looks for KB896358" date="2007-10-04T09:48:00.040-04:00">
              <contributor organization="Secure Elements, Inc.">Jeff Ito</contributor>
            </modified>
            <status_change date="2007-10-04T09:50:41.144-04:00">INTERIM</status_change>
            <status_change date="2007-10-22T08:53:27.646-04:00">ACCEPTED</status_change>
            <modified comment="Corrected and tightened regular expression in ste:2610" date="2010-12-02T11:46:00.307-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-12-02T11:47:27.567-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:58.783-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:44:52.140-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:03:02.244-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 (sp4 or earlier) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 5 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2790"/>
        </criteria>
        <criterion comment="the version of hh.exe is less than 5.2.3790.309" negate="false" test_ref="oval:org.mitre.oval:tst:2613"/>
        <criterion comment="the patch kb896358 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2668"/>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:462" version="10">
      <metadata>
        <title>FTP Server Command Injection Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference ref_id="CVE-2004-1166" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1166" source="CVE"/>
        <description>CRLF injection vulnerability in Microsoft Internet Explorer 6.0.2800.1106 and earlier allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline ("%0a") before the FTP command, which causes the commands to be inserted into the resulting FTP session, as demonstrated using a PORT command.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:27.314-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:41.334-04:00">ACCEPTED</status_change>
            <modified comment="Added an anchor to the regex used to check for Internet Explorer 6." date="2007-01-11T20:38:00.950-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-01-11T20:49:14.714-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:35.523-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:2185 - Anchored regular expression" date="2011-02-22T12:51:00.261-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:52:27.541-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:00:50.781-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:56.848-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:19.325-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:136 - modified comments" date="2014-02-28T15:13:00.247-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-28T15:16:20.709-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:19.785-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:95 - Addressed validation errors and duplicate extended definitions" date="2015-07-13T20:21:00.869-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:25:25.983-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:01:54.916-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Server 2003-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.554" negate="false" test_ref="oval:org.mitre.oval:tst:136"/>
        </criteria>
        <criteria comment="XP,SP1 (64-bit) and Server 2003, SP1" operator="AND">
          <criteria operator="OR" comment="Windows XP (64-bit,SP1) or Server 2003 (SP1) is installed">
            <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          </criteria>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2759" negate="false" test_ref="oval:org.mitre.oval:tst:175"/>
        </criteria>
        <criteria comment="IE 6 on Windows XP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2900.2963" negate="false" test_ref="oval:org.mitre.oval:tst:95"/>
        </criteria>
        <criteria comment="IE 6 on Windows 2000 or XP,SP1 (32-bit)" operator="AND">
          <criteria operator="OR" comment="Win2K,SP4 or XP,SP1 (32-bit) is installed">
            <extend_definition comment="Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
            <extend_definition comment="Windows XP, SP1 is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          </criteria>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Internet Explorer 6 (any patch level) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2333"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1561" negate="false" test_ref="oval:org.mitre.oval:tst:56"/>
        </criteria>
        <criteria comment="IE 5.01,SP4 on Win2k,SP4" operator="AND">
          <extend_definition comment="Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Internet Explorer 5.01, SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3842.3000" negate="false" test_ref="oval:org.mitre.oval:tst:106"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:46" version="6" class="vulnerability" deprecated="true">
      <metadata>
        <title>DEPRECATED: IIS Help File Search Cross-site Scripting</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0074" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0074"/>
        <description>Cross-site scripting vulnerability in Help File search facility for Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to embed scripts into another user's session.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified comment="Multiple corrections and update to POSIX compatibility for ste:2884" date="2010-11-29T16:14:00.692-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-11-29T16:14:39.922-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:58.484-05:00">ACCEPTED</status_change>
            <modified comment="Use def:12356 instead" date="2011-01-20T10:14:55.330-05:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-01-20T10:14:55.330-05:00">DEPRECATED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="the version of w3svc.dll is less than 5.0.2195.5269" negate="false" test_ref="oval:org.mitre.oval:tst:3080"/>
        <criterion comment="Patch Q319733 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3095"/>
        <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
        <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
        <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3079"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4593" version="6" class="vulnerability">
      <metadata>
        <title>Windows 2000 Access Requests Privilege Escalation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0061" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0061"/>
        <description>The kernel of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via certain access requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-02T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2005-05-04T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-06-17T12:00:00.000-04:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2005-07-27T10:37:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected and tightened regular expression in ste:2610" date="2010-12-02T11:46:00.307-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-12-02T11:47:26.925-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:58.214-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:44:55.259-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:03:01.852-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 (sp4 or earlier) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 5 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2790"/>
        </criteria>
        <criterion comment="The version of Ntoskrnl.exe is less than 5.0.2195.7035" negate="false" test_ref="oval:org.mitre.oval:tst:2358"/>
        <criterion comment="the patch KB890859 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2737"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4582" version="5" class="vulnerability">
      <metadata>
        <title>Uninitialized Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3902" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3902"/>
        <description>Use-after-free vulnerability in the CRecalcProperty function in mshtml.dll in Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code by calling the setExpression method and then modifying the outerHTML property of an HTML element, one variant of "Uninitialized Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2007-12-12T14:22:00">
              <contributor organization="Secure Elements, Inc.">Jeff Ito</contributor>
            </submitted>
            <status_change date="2007-12-14T15:11:04.550-05:00">DRAFT</status_change>
            <status_change date="2007-12-31T04:01:30.427-05:00">INTERIM</status_change>
            <status_change date="2008-02-04T10:17:07.911-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:4582 - Correcting incorrect references to 64-bit Itanium XP." date="2012-08-23T17:47:00.168-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-08-23T17:52:04.566-04:00">INTERIM</status_change>
            <status_change date="2012-09-10T04:00:56.101-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:48.560-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:19.117-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 5.01,SP4 on Win2k,SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3858.1100" test_ref="oval:org.mitre.oval:tst:6074"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win 2k, SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1605" test_ref="oval:org.mitre.oval:tst:6567"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win XP SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2900.3243" test_ref="oval:org.mitre.oval:tst:6855"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win S03 SP1">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.4186" test_ref="oval:org.mitre.oval:tst:6177"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win S03 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.4186" test_ref="oval:org.mitre.oval:tst:6730"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win XP SP1 (64-bit)">
          <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.4186" test_ref="oval:org.mitre.oval:tst:6177"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win XP SP2 (64-bit)">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.4186" test_ref="oval:org.mitre.oval:tst:6730"/>
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 on all platforms">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="the version of mshtml.dll is less than 7.0.6000.16587" test_ref="oval:org.mitre.oval:tst:6852"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:456" class="vulnerability" version="1">
      <metadata>
        <title>HTML Rendering Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4687" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4687"/>
        <description>Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via crafted layout combinations involving DIV tags and HTML CSS float properties that trigger memory corruption, aka "HTML Rendering Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-11-15T12:28:05">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-11-17T12:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:53:57.976-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:34.720-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Server 2003-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.594" negate="false" test_ref="oval:org.mitre.oval:tst:71"/>
        </criteria>
        <criteria comment="XP,SP1 (64-bit) and Server 2003, SP1" operator="AND">
          <criteria operator="OR" comment="Windows XP (64-bit,SP1) or Server 2003 (SP1) is installed">
            <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          </criteria>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2795" negate="false" test_ref="oval:org.mitre.oval:tst:70"/>
        </criteria>
        <criteria comment="IE 6 on Windows XP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2900.2995" negate="false" test_ref="oval:org.mitre.oval:tst:66"/>
        </criteria>
        <criteria comment="IE 6 on Windows 2000" operator="AND">
          <extend_definition comment="Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1578" negate="false" test_ref="oval:org.mitre.oval:tst:65"/>
        </criteria>
        <criteria comment="IE 5.01,SP4 on Win2k,SP4 (disagrees with bulletin, but needed to match MBSA results)" operator="AND">
          <extend_definition comment="Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Internet Explorer 5.01, SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3842.3000" negate="false" test_ref="oval:org.mitre.oval:tst:142"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4553" version="5" class="vulnerability">
      <metadata>
        <title>Uninitialized Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3903" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3903"/>
        <description>Microsoft Internet Explorer 6 and 7 allows remote attackers to execute arbitrary code via uninitialized or deleted objects used in repeated calls to the (1) cloneNode or (2) nodeValue JavaScript function, a different issue than CVE-2007-3902 and CVE-2007-5344, a variant of "Uninitialized Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2007-12-12T14:22:00">
              <contributor organization="Secure Elements, Inc.">Jeff Ito</contributor>
            </submitted>
            <status_change date="2007-12-14T15:11:05.011-05:00">DRAFT</status_change>
            <status_change date="2007-12-31T04:01:23.124-05:00">INTERIM</status_change>
            <status_change date="2008-02-04T10:17:01.957-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:4553 - Correcting incorrect references to 64-bit Itanium XP." date="2012-08-23T17:47:00.168-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-08-23T17:52:45.379-04:00">INTERIM</status_change>
            <status_change date="2012-09-10T04:00:55.488-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:51.137-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:18.978-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 on Win 2k, SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1605" test_ref="oval:org.mitre.oval:tst:6567"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win XP SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2900.3243" test_ref="oval:org.mitre.oval:tst:6855"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win S03 SP1">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.4186" test_ref="oval:org.mitre.oval:tst:6177"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win S03 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.4186" test_ref="oval:org.mitre.oval:tst:6730"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win XP SP1 (64-bit)">
          <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.4186" test_ref="oval:org.mitre.oval:tst:6177"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win XP SP2 (64-bit)">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.4186" test_ref="oval:org.mitre.oval:tst:6730"/>
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 on all platforms">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="the version of mshtml.dll is less than 7.0.6000.16587" test_ref="oval:org.mitre.oval:tst:6852"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4520" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft DirectX Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>DirectX</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3901" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3901"/>
        <description>Stack-based buffer overflow in the DirectShow Synchronized Accessible Media Interchange (SAMI) parser in quartz.dll for Microsoft DirectX 7.0 through 10.0 allows remote attackers to execute arbitrary code via a crafted SAMI file.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-12-14T18:18:00">
              <contributor organization="Secure Elements, Inc.">Jeff Ito</contributor>
            </submitted>
            <status_change date="2007-12-14T15:11:06.380-05:00">DRAFT</status_change>
            <status_change date="2007-12-31T04:01:13.963-05:00">INTERIM</status_change>
            <status_change date="2008-02-04T10:16:55.664-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:3502 - obj/ste updates to conform to authoring style guide" date="2013-03-26T09:53:00.500-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-03-26T09:55:58.103-04:00">INTERIM</status_change>
            <status_change date="2013-04-15T04:00:23.105-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software section">
        <criteria operator="AND" comment="DirectX 7 on Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="DirectX 7.0x Installed" test_ref="oval:org.mitre.oval:tst:1296"/>
          <criterion comment="the version of Quartz.dll is less than 6.1.9.733" test_ref="oval:org.mitre.oval:tst:6029"/>
        </criteria>
        <criteria operator="AND" comment="DirectX 8.1 on Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="DirectX 8.1 Installed" test_ref="oval:org.mitre.oval:tst:6805"/>
          <criterion comment="the version of Quartz.dll is less than 6.3.1.890" test_ref="oval:org.mitre.oval:tst:6230"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:451" version="7" class="vulnerability">
      <metadata>
        <title>Windows ListView Shatter Message Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Utilities Manager/Windows Messaging</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0350" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0350"/>
        <description>The control for listing accessibility options in the Accessibility Utility Manager on Windows 2000 (ListView) does not properly handle Windows messages, which allows local users to execute arbitrary code via a "Shatter" style message to the Utility Manager that references a user-controlled callback function.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-09T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-03-07T12:00:00.000-04:00" comment="modified wrt-222 - changed pattern match">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-03-09T07:55:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-29T07:59:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Multiple corrections and update to POSIX compatibility for ste:2878" date="2010-11-29T16:13:00.904-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-11-29T16:14:04.155-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:57.841-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:44:54.913-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:03:00.883-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="the version of sp3res.dll is less than 5.0.2195.6713" negate="false" test_ref="oval:org.mitre.oval:tst:2621"/>
        <criterion comment="the version of umandlg.dll is less than 1.0.0.3" negate="false" test_ref="oval:org.mitre.oval:tst:2620"/>
        <criterion comment="Patch KB822679 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2619"/>
        <criterion comment="SP4 or later Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3073"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4480" version="5" class="vulnerability">
      <metadata>
        <title>Uninitialized Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5344" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5344"/>
        <description>Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code via a crafted website using Javascript that creates, modifies, deletes, and accesses document objects using the tags property, which triggers heap corruption, related to uninitialized or deleted objects, a different issue than CVE-2007-3902 and CVE-2007-3903, and a variant of "Uninitialized Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2007-12-12T14:22:00">
              <contributor organization="Secure Elements, Inc.">Jeff Ito</contributor>
            </submitted>
            <status_change date="2007-12-14T15:11:05.514-05:00">DRAFT</status_change>
            <status_change date="2007-12-31T04:01:06.814-05:00">INTERIM</status_change>
            <status_change date="2008-02-04T10:16:51.099-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:4480 - Correcting incorrect references to 64-bit Itanium XP." date="2012-08-23T17:47:00.168-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-08-23T17:52:58.912-04:00">INTERIM</status_change>
            <status_change date="2012-09-10T04:00:54.913-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:49.087-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:18.837-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 on Win 2k, SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1605" test_ref="oval:org.mitre.oval:tst:6567"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win XP SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2900.3243" test_ref="oval:org.mitre.oval:tst:6855"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win S03 SP1">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.4186" test_ref="oval:org.mitre.oval:tst:6177"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win S03 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.4186" test_ref="oval:org.mitre.oval:tst:6730"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win XP SP1 (64-bit)">
          <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.4186" test_ref="oval:org.mitre.oval:tst:6177"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win XP SP2 (64-bit)">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.4186" test_ref="oval:org.mitre.oval:tst:6730"/>
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 on all platforms">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="the version of mshtml.dll is less than 7.0.6000.16587" test_ref="oval:org.mitre.oval:tst:6852"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4474" version="6" class="vulnerability">
      <metadata>
        <title>Vulnerability in Message Queuing Could Allow Remote Code Execution</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3039" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3039"/>
        <description>Stack-based buffer overflow in the Microsoft Message Queuing (MSMQ) service in Microsoft Windows 2000 Server SP4, Windows 2000 Professional SP4, and Windows XP SP2 allows attackers to execute arbitrary code via a long string in an opnum 0x06 RPC call to port 2103.  NOTE: this is remotely exploitable on Windows 2000 Server.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-12-13T08:28:45">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-12-13T15:20:52.132-05:00">DRAFT</status_change>
            <status_change date="2007-12-31T04:01:04.971-05:00">INTERIM</status_change>
            <status_change date="2008-02-04T10:16:49.922-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:4474 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:05:41.576-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:33.781-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:6760 - modified comments" date="2014-02-28T15:13:00.247-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-28T15:16:19.443-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:19.635-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win2K,SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="mqrt.dll version is less than 5.0.0.805" test_ref="oval:org.mitre.oval:tst:6814"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="mqrt.dll version is less than 5.1.0.1109" test_ref="oval:org.mitre.oval:tst:6760"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:444" version="4" class="vulnerability">
      <metadata>
        <title>IE v6.0 Temporary Internet Files folders Name Reading Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1188" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1188"/>
        <description>Internet Explorer 5.01 through 6.0 allows remote attackers to identify the path to the Temporary Internet Files folder and obtain user information such as cookies via certain uses of the OBJECT tag, which are not subjected to the proper security checks, aka "Temporary Internet Files folders Name Reading."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-27T05:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-03-09T05:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Changed IE registry test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:59.361-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:18.732-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the version of mshtml.dll is less than 6.0.2722.900" negate="false" test_ref="oval:org.mitre.oval:tst:2884"/>
        <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
        <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
        <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:44" version="5" class="vulnerability">
      <metadata>
        <title>IIS Web Server Folder Traversal</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2000-0884" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0884"/>
        <description>IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary commands, via malformed URLs that contain UNICODE encoded characters, aka the "Web Server Folder Traversal" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified comment="Updated comment to include Vista and Server 2008" date="2009-05-07T10:32:00.713-04:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2009-05-07T10:34:09.521-04:00">INTERIM</status_change>
            <status_change date="2009-05-25T04:01:30.278-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:13.122-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:02:59.232-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Software section">
        <criterion comment="IIS major version equals 5" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS minor version equals 0" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="File %windir%\system32\inetsrv\w3svc.dll version is less than 5.0.2195.2103" test_ref="oval:org.mitre.oval:tst:3023"/>
        <criterion negate="true" comment="Patch Q269862 Installed" test_ref="oval:org.mitre.oval:tst:3022"/>
        <criterion negate="true" comment="Patch Q277873 Installed" test_ref="oval:org.mitre.oval:tst:3021"/>
        <criterion negate="true" comment="Patch Q293826 Installed" test_ref="oval:org.mitre.oval:tst:3020"/>
        <criterion negate="true" comment="Patch Q301625 Installed" test_ref="oval:org.mitre.oval:tst:3037"/>
        <criterion negate="true" comment="Patch Q319733 Installed" test_ref="oval:org.mitre.oval:tst:3095"/>
        <criterion negate="true" comment="Patch Q327696 Installed" test_ref="oval:org.mitre.oval:tst:3094"/>
        <criterion negate="true" comment="Patch Q811114 Installed" test_ref="oval:org.mitre.oval:tst:3093"/>
        <criterion negate="true" comment="Win2K/XP/2003/Vista/2008 Service Pack 2 is installed" test_ref="oval:org.mitre.oval:tst:3019"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4395" version="3" class="vulnerability">
      <metadata>
        <title>Vulnerability in DNS Could Allow Spoofing</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3898" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3898"/>
        <description>The DNS server in Microsoft Windows 2000 Server SP4, and Server 2003 SP1 and SP2, uses predictable transaction IDs when querying other DNS servers, which allows remote attackers to spoof DNS replies, poison the DNS cache, and facilitate further attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-11-16T05:29:38">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-11-16T07:50:52.862-05:00">DRAFT</status_change>
            <modified comment="Set datatype to version on ste:3941" date="2007-11-20T07:54:00.214-05:00">
              <contributor organization="Hewlett-Packard">Jeff Cheng</contributor>
            </modified>
            <modified comment="Set datatype to version on ste:2989" date="2007-11-20T07:54:00.087-05:00">
              <contributor organization="Hewlett-Packard">Jeff Cheng</contributor>
            </modified>
            <modified comment="Set datatype to version on ste:3153" date="2007-11-20T07:54:00.404-05:00">
              <contributor organization="Hewlett-Packard">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-12-10T04:00:10.833-05:00">INTERIM</status_change>
            <status_change date="2007-12-31T04:00:52.042-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:4395 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:05:51.177-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:33.416-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win2K,SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of dns.exe is less than 5.0.2195.7147" test_ref="oval:org.mitre.oval:tst:6861"/>
        </criteria>
        <criteria operator="AND" comment="S03,SP1">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of dns.exe is less than 5.2.3790.3027" test_ref="oval:org.mitre.oval:tst:6845"/>
        </criteria>
        <criteria operator="AND" comment="S03,SP2">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <criterion comment="the version of dns.exe is less than 5.2.3790.4171" test_ref="oval:org.mitre.oval:tst:6535"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:437" class="vulnerability" version="1">
      <metadata>
        <title>DirectAnimation ActiveX Controls Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4446" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4446"/>
        <description>Heap-based buffer overflow in DirectAnimation.PathControl COM object (daxctle.ocx) in Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a Spline function call whose first argument specifies a large number of points.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-11-15T12:28:05">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-11-17T12:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:53:57.418-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:33.869-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Server 2003-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.594" negate="false" test_ref="oval:org.mitre.oval:tst:71"/>
        </criteria>
        <criteria comment="XP,SP1 (64-bit) and Server 2003, SP1" operator="AND">
          <criteria operator="OR" comment="Windows XP (64-bit,SP1) or Server 2003 (SP1) is installed">
            <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          </criteria>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2795" negate="false" test_ref="oval:org.mitre.oval:tst:70"/>
        </criteria>
        <criteria comment="IE 6 on Windows XP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2900.2995" negate="false" test_ref="oval:org.mitre.oval:tst:66"/>
        </criteria>
        <criteria comment="IE 6 on Windows 2000" operator="AND">
          <extend_definition comment="Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1578" negate="false" test_ref="oval:org.mitre.oval:tst:65"/>
        </criteria>
        <criteria comment="IE 5.01,SP4 on Win2k,SP4" operator="AND">
          <extend_definition comment="Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Internet Explorer 5.01, SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3842.3000" negate="false" test_ref="oval:org.mitre.oval:tst:142"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4363" version="4" class="vulnerability">
      <metadata>
        <title>IE v5.01, SP3 HijackClick 3 / Script in Image Tag File Download Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0841" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0841"/>
        <description>Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" and the "Script in Image Tag File Download Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-01-20T02:31:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2824. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:48:00.494-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:52:24.290-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:33.504-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:54.389-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:18.632-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3015"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3821.2800" negate="false" test_ref="oval:org.mitre.oval:tst:625"/>
          <criterion comment="the patch kb834707-ie501sp3 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:624"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:435" version="2" class="vulnerability">
      <metadata>
        <title>Internet Information Services using Malformed Active Server Pages Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference ref_id="CVE-2006-0026" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0026" source="CVE"/>
        <description>Buffer overflow in Microsoft Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows local and possibly remote attackers to execute arbitrary code via crafted Active Server Pages (ASP).</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-27T12:29:26.215-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:40.456-04:00">ACCEPTED</status_change>
            <modified comment="Windows XP 64bit does not install IIS 5.1, rather it installs 6.0" date="2008-02-04T10:01:00.293-05:00">
              <contributor organization="Lumension Security, Inc.">Ken Lassesen</contributor>
            </modified>
            <status_change date="2008-02-04T10:03:21.323-05:00">INTERIM</status_change>
            <status_change date="2008-02-25T04:00:08.981-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win2K,SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft IIS 5.0 is installed" definition_ref="oval:org.mitre.oval:def:731"/>
          <criterion comment="File %windir%\system32\inetsrv\asp.dll version is less than 5.0.2195.7084" test_ref="oval:org.mitre.oval:tst:78"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP1">
          <extend_definition comment="Microsoft Windows XP SP1 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          <extend_definition comment="Microsoft IIS 5.1 is installed" definition_ref="oval:org.mitre.oval:def:460"/>
          <criterion comment="File %windir%\system32\inetsrv\asp.dll version is less than 5.1.2600.1829" test_ref="oval:org.mitre.oval:tst:9"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Microsoft IIS 5.1 is installed" definition_ref="oval:org.mitre.oval:def:460"/>
          <criterion comment="File %windir%\system32\inetsrv\asp.dll version is less than 5.1.2600.2889" test_ref="oval:org.mitre.oval:tst:157"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP1 (64-bit)">
          <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <extend_definition comment="Microsoft IIS 6.0 is installed" definition_ref="oval:org.mitre.oval:def:227"/>
          <criterion comment="File %windir%\system32\inetsrv\asp.dll version is less than 6.0.3790.2684" test_ref="oval:org.mitre.oval:tst:108"/>
        </criteria>
        <criteria operator="AND" comment="S03-Gold">
          <extend_definition comment="Microsoft Windows Server 2003 (x86) Gold is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <extend_definition comment="Microsoft IIS 6.0 is installed" definition_ref="oval:org.mitre.oval:def:227"/>
          <criterion comment="File %windir%\system32\inetsrv\asp.dll version is less than 6.0.3790.520" test_ref="oval:org.mitre.oval:tst:144"/>
        </criteria>
        <criteria operator="AND" comment="S03,SP1">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <extend_definition comment="Microsoft IIS 6.0 is installed" definition_ref="oval:org.mitre.oval:def:227"/>
          <criterion comment="File %windir%\system32\inetsrv\asp.dll version is less than 6.0.3790.2684" test_ref="oval:org.mitre.oval:tst:108"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:227" version="4" class="inventory">
      <metadata>
        <title>Microsoft IIS 6.0 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft IIS 6.0</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:iis:6.0"/>
        <description>The application Microsoft IIS 6.0 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-27T12:29:16.652-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:35.614-04:00">ACCEPTED</status_change>
            <modified comment="Added CPE reference." date="2007-04-30T07:48:00.336-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-30T08:13:22.361-04:00">INTERIM</status_change>
            <status_change date="2007-05-23T15:05:39.977-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:227 - product info corrected" date="2015-04-15T12:33:00.646-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-04-15T12:36:19.941-04:00">INTERIM</status_change>
            <status_change date="2015-05-04T04:00:14.871-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="IIS Major Version equals 6" test_ref="oval:org.mitre.oval:tst:170"/>
        <criterion comment="IIS Minor Version equals 0" test_ref="oval:org.mitre.oval:tst:164"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4345" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 Long Share Names Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows Shell</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0214" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0214"/>
        <description>Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of service (application crash) and possibly execute arbitrary code via long share names, as demonstrated using Samba.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-14T03:38:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="the version of shell32.dll is less than 5.0.3900.6970" negate="false" test_ref="oval:org.mitre.oval:tst:332"/>
        <criterion comment="the patch q841356 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:739"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4332" version="5" class="vulnerability">
      <metadata>
        <title>Uninitialized Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5347" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5347"/>
        <description>Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code via "unexpected method calls to HTML objects," aka "DHTML Object Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2007-12-12T14:22:00">
              <contributor organization="Secure Elements, Inc.">Jeff Ito</contributor>
            </submitted>
            <status_change date="2007-12-14T15:11:09.631-05:00">DRAFT</status_change>
            <status_change date="2007-12-31T04:00:42.291-05:00">INTERIM</status_change>
            <status_change date="2008-02-04T10:16:34.788-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:4332 - Correcting incorrect references to 64-bit Itanium XP." date="2012-08-23T17:47:00.168-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-08-23T17:52:02.188-04:00">INTERIM</status_change>
            <status_change date="2012-09-10T04:00:54.206-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:56.080-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:18.466-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 on Win 2k, SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1605" test_ref="oval:org.mitre.oval:tst:6567"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win XP SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2900.3243" test_ref="oval:org.mitre.oval:tst:6855"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win S03 SP1">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.4186" test_ref="oval:org.mitre.oval:tst:6177"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win S03 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.4186" test_ref="oval:org.mitre.oval:tst:6730"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win XP SP1 (64-bit)">
          <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.4186" test_ref="oval:org.mitre.oval:tst:6177"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win XP SP2 (64-bit)">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.4186" test_ref="oval:org.mitre.oval:tst:6730"/>
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 on all platforms">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="the version of mshtml.dll is less than 7.0.6000.16587" test_ref="oval:org.mitre.oval:tst:6852"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:433" version="10" class="vulnerability">
      <metadata>
        <title>HTML Layout and Positioning Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference ref_id="CVE-2006-3450" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3450" source="CVE"/>
        <description>Microsoft Internet Explorer 6 allows remote attackers to execute arbitrary code by using the document.getElementByID Javascript function to access crafted Cascading Style Sheet (CSS) elements, and possibly other unspecified vectors involving certain layout positioning combinations in an HTML file.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:25.864-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:39.996-04:00">ACCEPTED</status_change>
            <modified comment="Added an anchor to the regex used to check for Internet Explorer 6." date="2007-01-11T20:38:00.950-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-01-11T20:49:16.872-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:33.194-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:2185 - Anchored regular expression" date="2011-02-22T12:51:00.261-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:52:28.327-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:00:50.278-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:46.406-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:18.312-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:136 - modified comments" date="2014-02-28T15:13:00.247-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-28T15:16:20.805-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:19.439-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:433 - Addressed validation errors and duplicate extended definitions" date="2015-07-13T20:21:00.869-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:25:23.778-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:01:54.684-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Server 2003-Gold">
          <extend_definition comment="Microsoft Windows Server 2003 (x86) Gold is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.554" test_ref="oval:org.mitre.oval:tst:136"/>
        </criteria>
        <criteria comment="XP,SP1 (64-bit) and Server 2003, SP1">
          <criteria operator="OR" comment="Windows XP (64-bit,SP1) or Server 2003 (SP1) is installed">
            <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2759" test_ref="oval:org.mitre.oval:tst:175"/>
        </criteria>
        <criteria comment="IE 6 on Windows XP,SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.2963" test_ref="oval:org.mitre.oval:tst:95"/>
        </criteria>
        <criteria comment="IE 6 on Windows 2000 or XP,SP1 (32-bit)">
          <criteria operator="OR" comment="Win2K,SP4 or XP,SP1 (32-bit) is installed">
            <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
            <extend_definition comment="Microsoft Windows XP SP1 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1561" test_ref="oval:org.mitre.oval:tst:56"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4316" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 VDM Privilege Escalation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>VDM</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0208" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0208"/>
        <description>The Virtual DOS Machine (VDM) subsystem of Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to access kernel memory and gain privileges via a malicious program that modified some system structures in a way that is not properly validated by privileged operating system functions.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-13T11:08:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-10-13T01:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-10-27T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-11-17T10:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="the version of vdmdbg.dll is less than 5.0.2195.6946" negate="false" test_ref="oval:org.mitre.oval:tst:333"/>
        <criterion comment="the patch KB840987 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2356"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4307" version="6" class="vulnerability">
      <metadata>
        <title>GDI+ JPEG Parsing Engine Buffer Overflow (VS.NET 2002)</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Visual Studio .NET 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0200" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0200"/>
        <description>Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-09-30T11:37:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-10-06T12:57:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-10-20T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed test to check KB830348.  Added check for VS.NET Gdiplus.dll in WinSxS.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 303 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-28T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:47.358-04:00">ACCEPTED</status_change>
            <modified comment="var:228 updated: reference to windir environment variable object obj:577 replaced with obj:219, the registry object for SystemRoot.  Literal component now starts with a backslash.  Implemented by Harvey Rubinovitz." date="2007-01-05T16:46:00.401-05:00">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2007-01-05T16:52:19.766-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:32.512-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:755 - Updating criterion logic and check attributes for Gdiplus.dll related Objects." date="2013-12-30T09:14:00.018-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-30T09:17:36.661-05:00">INTERIM</status_change>
            <status_change date="2014-01-20T04:01:19.269-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Microsoft Visual Studio .NET 2002 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:334"/>
        <criterion comment="the version of Gdiplus.dll for Microsoft Visual Studio .NET is less than 5.1.3102.1355" negate="false" test_ref="oval:org.mitre.oval:tst:755"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4287" version="6" class="vulnerability">
      <metadata>
        <title>Microsoft DirectX Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>DirectX</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3895" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3895"/>
        <description>Buffer overflow in Microsoft DirectShow in Microsoft DirectX 7.0 through 10.0 allows remote attackers to execute arbitrary code via a crafted (1) WAV or (2) AVI file.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-12-13T20:49:00">
              <contributor organization="Secure Elements, Inc.">Jeff Ito</contributor>
            </submitted>
            <status_change date="2007-12-14T15:11:07.454-05:00">DRAFT</status_change>
            <status_change date="2007-12-31T04:00:36.732-05:00">INTERIM</status_change>
            <status_change date="2008-02-04T10:16:31.515-05:00">ACCEPTED</status_change>
            <modified comment="Updated to reflect Microsoft's updating of MS07-064 and MS08-033 which now declares DirectX 9.0a, 9.0b, and 9.0c vulnerable." date="2008-07-18T10:12:00.356-04:00">
              <contributor organization="Secure Elements, Inc.">Jeff Ito</contributor>
            </modified>
            <status_change date="2008-07-18T10:16:39.371-04:00">INTERIM</status_change>
            <status_change date="2008-08-04T04:00:10.541-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:4287 - Correcting incorrect references to 64-bit Itanium XP." date="2012-08-23T17:47:00.168-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-08-23T17:52:16.652-04:00">INTERIM</status_change>
            <status_change date="2012-09-10T04:00:53.406-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:3502 - obj/ste updates to conform to authoring style guide" date="2013-03-26T09:53:00.500-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-03-26T09:55:59.604-04:00">INTERIM</status_change>
            <status_change date="2013-04-15T04:00:21.182-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="DirectX 7 on Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="DirectX 7.0x Installed" test_ref="oval:org.mitre.oval:tst:1296"/>
          <criterion comment="the version of Quartz.dll is less than 6.1.9.733" test_ref="oval:org.mitre.oval:tst:6029"/>
        </criteria>
        <criteria operator="AND" comment="DirectX 8.1 on Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="DirectX 8.1 Installed" test_ref="oval:org.mitre.oval:tst:6805"/>
          <criterion comment="the version of Quartz.dll is less than 6.3.1.890" test_ref="oval:org.mitre.oval:tst:6230"/>
        </criteria>
        <criteria operator="AND" comment="DirectX 9.0c on Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="DirectX 9.0x Installed" test_ref="oval:org.mitre.oval:tst:601"/>
          <criterion comment="the version of Quartz.dll is less than 6.5.1.908" test_ref="oval:org.mitre.oval:tst:6541"/>
        </criteria>
        <criteria operator="AND" comment="DirectX 9.0c on Win XP SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="DirectX 9.0x Installed" test_ref="oval:org.mitre.oval:tst:601"/>
          <criterion comment="the version of Quartz.dll is less than 6.5.2600.3243" test_ref="oval:org.mitre.oval:tst:6770"/>
        </criteria>
        <criteria operator="AND" comment="DirectX 9.0c on Win XP SP1 64bit">
          <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="DirectX 9.0x Installed" test_ref="oval:org.mitre.oval:tst:601"/>
          <criterion comment="the version of Quartz.dll is less than 6.5.3790.3035" test_ref="oval:org.mitre.oval:tst:6513"/>
        </criteria>
        <criteria operator="AND" comment="DirectX 9.0c on Win XP SP2 64bit">
          <criterion comment="DirectX 9.0x Installed" test_ref="oval:org.mitre.oval:tst:601"/>
          <criterion comment="the version of Quartz.dll is less than 6.5.3790.4178" test_ref="oval:org.mitre.oval:tst:6203"/>
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
        </criteria>
        <criteria operator="AND" comment="DirectX 9.0c on 2003">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
          </criteria>
          <criterion comment="DirectX 9.0x Installed" test_ref="oval:org.mitre.oval:tst:601"/>
          <criterion comment="the version of Quartz.dll is less than 6.5.3790.3035" test_ref="oval:org.mitre.oval:tst:6513"/>
        </criteria>
        <criteria operator="AND" comment="DirectX 9.0c on 2003 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="DirectX 9.0x Installed" test_ref="oval:org.mitre.oval:tst:601"/>
          <criterion comment="the version of Quartz.dll is less than 6.5.3790.4178" test_ref="oval:org.mitre.oval:tst:6203"/>
        </criteria>
        <criteria operator="AND" comment="DirectX 10.0 on Vista">
          <extend_definition comment="Microsoft Windows Vista is installed" definition_ref="oval:org.mitre.oval:def:228"/>
          <criterion comment="the version of Quartz.dll is less than 6.6.6000.16587" test_ref="oval:org.mitre.oval:tst:6690"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:428" version="4" class="vulnerability">
      <metadata>
        <title>Server Service Denial of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference ref_id="CVE-2006-3942" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3942" source="CVE"/>
        <description>The server driver (srv.sys) in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service (system crash) via an SMB_COM_TRANSACTION SMB message that contains a string without null character termination, which leads to a NULL dereference in the ExecuteTransaction function, possibly related to an "SMB PIPE," aka the "Mailslot DOS" vulnerability.  NOTE: the name "Mailslot DOS" was derived from incomplete initial research; the vulnerability is not associated with a mailslot.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-10-11T05:29:41">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-13T14:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-31T19:35:40.466-05:00">INTERIM</status_change>
            <status_change date="2006-11-21T21:27:49.665-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:428 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:06:35.441-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:32.894-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win2K,SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of srv.sys is less than 5.0.2195.7106" test_ref="oval:org.mitre.oval:tst:37"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP1">
          <extend_definition comment="Microsoft Windows XP SP1 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          <criterion comment="the version of srv.sys is less than 5.1.2600.1885" test_ref="oval:org.mitre.oval:tst:39"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of srv.sys is less than 5.1.2600.2974" test_ref="oval:org.mitre.oval:tst:111"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP1 (64-bit)">
          <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="the version of srv.sys is less than 5.2.3790.2783" test_ref="oval:org.mitre.oval:tst:40"/>
        </criteria>
        <criteria operator="AND" comment="S03-Gold">
          <extend_definition comment="Microsoft Windows Server 2003 (x86) Gold is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="the version of srv.sys is less than 5.2.3790.588" test_ref="oval:org.mitre.oval:tst:41"/>
        </criteria>
        <criteria operator="AND" comment="S03,SP1">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of srv.sys is less than 5.2.3790.2783" test_ref="oval:org.mitre.oval:tst:40"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4264" version="4" class="vulnerability">
      <metadata>
        <title>ISA Server Reverse DNS Lookup Results Spoofing</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Security and Acceleration Server 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0892" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0892"/>
        <description>Microsoft Proxy Server 2.0 and Microsoft ISA Server 2000 (which is included in Small Business Server 2000 and Small Business Server 2003 Premium Edition) allows remote attackers to spoof trusted Internet content on a specially crafted webpage via spoofed reverse DNS lookup results.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-11-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-12T12:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T09:25:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-24T12:00:00.000-04:00" comment="modified var 208 to correctly point at the ISA Server directory">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-24T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:25.022-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:4264 - Corrected capitalization and extra spacing errors in product names" date="2011-04-08T16:13:00.153-04:00">
              <contributor organization="AIST">Akihito Nakamura</contributor>
            </modified>
            <status_change date="2011-04-08T16:17:42.900-04:00">INTERIM</status_change>
            <status_change date="2011-04-25T04:00:19.862-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="the version of msphlpr.dll is less than 3.0.1200.408" test_ref="oval:org.mitre.oval:tst:338"/>
        <criterion comment="ISA Server 2000 SP2 (or earlier) is installed" test_ref="oval:org.mitre.oval:tst:2611"/>
        <criterion comment="the patch KB888258 is installed" test_ref="oval:org.mitre.oval:tst:337"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:424" version="1" class="vulnerability">
      <metadata>
        <title>Windows Telnet Server Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Telnet protocol</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0020" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0020"/>
        <description>Buffer overflow in telnet server in Windows 2000 and Interix 2.2 allows remote attackers to execute arbitrary code via malformed protocol options.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <modified date="2004-07-20T12:00:00.000-04:00" comment="Changed patch registry key value to IsInstalled">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-07-21T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-11T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="the version of tlntsvr.exe is less than 5.0.33668.1" negate="false" test_ref="oval:org.mitre.oval:tst:2644"/>
          <criterion comment="Patch Q307298 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2643"/>
          <criterion comment="Windows 2000 Security Roll-up 1 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2990"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the telnet service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2642"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4216" version="6" class="vulnerability">
      <metadata>
        <title>GDI+ JPEG Parsing Engine Buffer Overflow (IE6)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0200" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0200"/>
        <description>Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-04T09:55:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-10-06T12:57:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-10-20T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed test to check q833989, added check for vgx.dll.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:46:00.470-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:31.442-05:00">ACCEPTED</status_change>
            <modified comment="References registry value for Common Files directory due to multilingual support" date="2008-04-14T11:07:00.466-04:00">
              <contributor organization="GFI Software">Clifford Farrugia</contributor>
            </modified>
            <status_change date="2008-04-14T12:28:15.957-04:00">INTERIM</status_change>
            <status_change date="2008-05-05T04:00:21.326-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:34.063-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:18.221-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
        <criterion comment="the version of vgx.dll is less than 6.0.2800.1411" negate="false" test_ref="oval:org.mitre.oval:tst:341"/>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:419" version="2">
      <metadata>
        <title>.NET 2.0 Application Folder Information Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft .NET Framework</product>
        </affected>
        <reference ref_id="CVE-2006-1300" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1300" source="CVE"/>
        <description>Microsoft .NET framework 2.0 (ASP.NET) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1 allows remote attackers to bypass access restrictions via unspecified "URL paths" that can access Application Folder objects "explicitly by name."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-27T12:29:24.125-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:39.673-04:00">ACCEPTED</status_change>
            <modified comment="Corrected comment on tst:8. Added new state ste:98 to check the correct file version. Corrected file path and name specification in obj:180. Edits made by Jon Baker." date="2006-11-09T06:09:00.371-05:00">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2007-01-04T09:13:47.443-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:31.216-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft .NET Framework 2.0 (Original RTM or later) is installed" definition_ref="oval:org.mitre.oval:def:1934"/>
        <criterion comment="the version of Aspnet_filter.dll is less than 2.0.50727.101" test_ref="oval:org.mitre.oval:tst:8"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:416" version="4" class="vulnerability">
      <metadata>
        <title>IE v6.0,SP1 Script URLs Cross Domain Zone Restrictions Bypass</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0816" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0816"/>
        <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a file: URL containing Javascript, as demonstrated by NAFfileJPU, (2) using the window.open method to load a file: URL containing Javascript, as demonstrated using WsOpenFileJPU, (3) setting the href property in the base tag for the _search window, as demonstrated using WsBASEjpu, (4) loading the search window into an Iframe, as demonstrated using WsFakeSrc, (5) caching a javascript: URL in the browser history, then accessing that URL in the same frame as the target domain, as demonstrated using WsOpenJpuInHistory, NAFjpuInHistory, BackMyParent, BackMyParent2, and RefBack, aka the "Script URLs Cross Domain" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for specific Windows operating systems.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 sp1 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-01-29T12:00:00.000-04:00" comment="Added Windows XP 64-bit to the list of affected platforms">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:46:02.945-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:30.538-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:51.866-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:18.084-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1276" negate="false" test_ref="oval:org.mitre.oval:tst:2688"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4152" version="4" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP4 Drag-and-Drop Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0839" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0839"/>
        <description>Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by "wottapoop.html".</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-25T04:44:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-27T01:04:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-17T10:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed ste:2614: set datatype to version.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:54:00.319-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:59:43.670-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:30.285-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:49.015-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:18.005-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3534.2800" negate="false" test_ref="oval:org.mitre.oval:tst:519"/>
          <criterion comment="the patch kb834707-ie501sp4 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:518"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:413" class="vulnerability" version="1">
      <metadata>
        <title>Microsoft Client Service for NetWare Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>NetWare</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4689" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4689"/>
        <description>Unspecified vulnerability in the driver for the Client Service for NetWare (CSNW) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to cause a denial of service (hang and reboot) via has unknown attack vectors, aka "NetWare Driver Denial of Service Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-11-15T12:28:05">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-11-17T12:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:53:56.587-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:30.055-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Win2K,SP4" operator="AND">
          <extend_definition comment="Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of nwrdr.sys is less than 5.0.2195.7110" test_ref="oval:org.mitre.oval:tst:74"/>
        </criteria>
        <criteria comment="WinXP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of nwrdr.sys is less than 5.1.2600.3015" test_ref="oval:org.mitre.oval:tst:75"/>
        </criteria>
        <criteria comment="S03-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="The version of nwrdr.sys is less than 5.2.3790.588" test_ref="oval:org.mitre.oval:tst:84"/>
        </criteria>
        <criteria comment="S03,SP1" operator="AND">
          <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of nwrdr.sys is less than 5.2.3790.2783" test_ref="oval:org.mitre.oval:tst:76"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:409" version="3" class="vulnerability">
      <metadata>
        <title>IE v5.5,SP2 Script URLs Cross Domain Zone Restrictions Bypass</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0816" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0816"/>
        <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a file: URL containing Javascript, as demonstrated by NAFfileJPU, (2) using the window.open method to load a file: URL containing Javascript, as demonstrated using WsOpenFileJPU, (3) setting the href property in the base tag for the _search window, as demonstrated using WsBASEjpu, (4) loading the search window into an Iframe, as demonstrated using WsFakeSrc, (5) caching a javascript: URL in the browser history, then accessing that URL in the same frame as the target domain, as demonstrated using WsOpenJpuInHistory, NAFjpuInHistory, BackMyParent, BackMyParent2, and RefBack, aka the "Script URLs Cross Domain" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for specific Windows operating systems.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.5 sp2 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:53.916-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:17.934-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
          <criterion comment="the version of mshtml.dll is less than 5.50.4934.1600" negate="false" test_ref="oval:org.mitre.oval:tst:2689"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:408" version="3" class="vulnerability">
      <metadata>
        <title>IE v5.5 Cross Domain Verification via Cached Methods Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1254" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1254"/>
        <description>Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model and access information on the local system or in other domains, and possibly execute code, via cached methods and objects, aka "Cross Domain Verification via Cached Methods."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-27T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:54.037-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:17.813-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Internet Explorer 5.5 Installed">
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3078"/>
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3077"/>
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3076"/>
          <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
        </criteria>
        <criterion comment="the version of mshtml.dll is less than 5.50.4922.900" negate="false" test_ref="oval:org.mitre.oval:tst:2786"/>
        <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
        <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
        <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:406" version="2" class="vulnerability">
      <metadata>
        <title>Microsoft Winsock Proxy Service Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Security and Acceleration Server 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0110" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0110"/>
        <description>The Winsock Proxy service in Microsoft Proxy Server 2.0 and the Microsoft Firewall service in Internet Security and Acceleration (ISA) Server 2000 allow remote attackers to cause a denial of service (CPU consumption or packet storm) via a spoofed, malformed packet to UDP port 1745.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-12-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.657-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-10-25T16:50:13.984-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:01:15.559-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Software section">
          <criterion comment="ISA Server 2000 is installed" test_ref="oval:org.mitre.oval:tst:2935"/>
          <criterion comment="the version of w3proxy.exe is less than 3.0.1200.257" test_ref="oval:org.mitre.oval:tst:2662"/>
          <criterion comment="the version of wpsrv.exe is less than 3.0.1200.257" test_ref="oval:org.mitre.oval:tst:2661"/>
          <criterion negate="true" comment="Patch isahf257 installed" test_ref="oval:org.mitre.oval:tst:2660"/>
        </criteria>
        <criteria operator="AND" comment="Configuration section">
          <criterion comment="Microsoft Firewall Service Enabled" test_ref="oval:org.mitre.oval:tst:2659"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4043" version="8" class="vulnerability">
      <metadata>
        <title>SMB Code Execution Vulnerability (Windows 2000)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>SMB (Server Message Block)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0045" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0045"/>
        <description>The Server Message Block (SMB) implementation for Windows NT 4.0, 2000, XP, and Server 2003 does not properly validate certain SMB packets, which allows remote attackers to execute arbitrary code via Transaction responses containing (1) Trans or (2) Trans2 commands, aka the "Server Message Block Vulnerability," and as demonstrated using Trans2 FIND_FIRST2 responses with large file name length fields.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-02-15T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-02-18T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-29T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-17T12:00:00.000-04:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2005-06-22T12:35:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">ACCEPTED</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.350-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-10-25T16:51:29.763-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:01:15.337-05:00">ACCEPTED</status_change>
            <modified comment="Corrected and tightened regular expression in ste:2610" date="2010-12-02T11:46:00.307-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-12-02T11:47:26.827-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:57.215-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:46:33.080-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:02:56.870-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 (sp4 or earlier) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 5 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2790"/>
        </criteria>
        <criterion comment="the version of mrxsmb.sys is less than 5.0.2195.7023" negate="false" test_ref="oval:org.mitre.oval:tst:359"/>
        <criterion comment="the patch KB885250 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:824"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:404" class="vulnerability" version="1">
      <metadata>
        <title>Microsoft Client Service for NetWare Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>NetWare</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4688" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4688"/>
        <description>Buffer overflow in Client Service for NetWare (CSNW) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via crafted messages, aka "Client Service for NetWare Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-11-15T12:28:05">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-11-17T12:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:53:56.358-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:29.545-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Win2K,SP4" operator="AND">
          <extend_definition comment="Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of nwrdr.sys is less than 5.0.2195.7110" test_ref="oval:org.mitre.oval:tst:74"/>
        </criteria>
        <criteria comment="WinXP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of nwrdr.sys is less than 5.1.2600.3015" test_ref="oval:org.mitre.oval:tst:75"/>
        </criteria>
        <criteria comment="S03-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="The version of nwrdr.sys is less than 5.2.3790.588" test_ref="oval:org.mitre.oval:tst:84"/>
        </criteria>
        <criteria comment="S03,SP1" operator="AND">
          <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of nwrdr.sys is less than 5.2.3790.2783" test_ref="oval:org.mitre.oval:tst:76"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4032" version="1" class="vulnerability">
      <metadata>
        <title>Exchange Server SMTP Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Exchange Server</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0560" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0560"/>
        <description>Heap-based buffer overflow in the SvrAppendReceivedChunk function in xlsasink.dll in the SMTP service of Exchange Server 2000 and 2003 allows remote attackers to execute arbitrary code via a crafted X-LINK2STATE extended verb request to the SMTP port.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-04-21T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-04-27T12:06:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Exchange Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:362"/>
        <criterion comment="the version of xlsasink.dll is less than 6.5.6981.3" negate="false" test_ref="oval:org.mitre.oval:tst:361"/>
        <criterion comment="the patch KB894549 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:360"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:403" version="7" class="vulnerability">
      <metadata>
        <title>Code Execution via Compiled HTML Help File</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>HTML Help Facility</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0694" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0694"/>
        <description>The HTML Help facility in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP uses the Local Computer Security Zone when opening .chm files from the Temporary Internet Files folder, which allows remote attackers to execute arbitrary code via HTML mail that references or inserts a malicious .chm file containing shortcuts that can be executed, aka "Code Execution via Compiled HTML Help File."</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-03-07T12:00:00.000-04:00" comment="modified wrt-222 - changed pattern match">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-03-09T07:55:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-29T07:59:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Multiple corrections and update to POSIX compatibility for ste:2878" date="2010-11-29T16:13:00.904-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-11-29T16:14:04.718-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:56.855-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:44:46.281-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:02:56.526-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="the version of hhsetup.dll is less than 5.2.3644.0" negate="false" test_ref="oval:org.mitre.oval:tst:2675"/>
        <criterion comment="the version of itircl.dll is less than 5.2.3644.0" negate="false" test_ref="oval:org.mitre.oval:tst:2674"/>
        <criterion comment="the version of itss.dll is less than 5.2.3644.0" negate="false" test_ref="oval:org.mitre.oval:tst:2673"/>
        <criterion comment="the patch q323255 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2672"/>
        <criterion comment="SP4 or later Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3073"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4022" version="2" class="vulnerability">
      <metadata>
        <title>Office XP URL Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Office XP SP3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0848" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0848"/>
        <description>Buffer overflow in Microsoft Office XP allows remote attackers to execute arbitrary code via a link with a URL file location containing long inputs after (1) "%00 (null byte) in .doc filenames or (2) "%0a" (carriage return) in .rtf filenames.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-02-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <modified date="2005-02-11T12:00:00.000-04:00" comment="Added patch check">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-03-29T12:00:00.000-04:00" comment="corrected patch negation">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2006-09-21T12:00:00.000-04:00" comment="removed tst:366 since it doesn't detect KB873352 correctly">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2005-03-29T08:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-13T12:15:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-05-04T12:33:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2006-09-21T12:15:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:46.501-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Microsoft Office XP Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1592"/>
        <criterion comment="the version of mso.dll is less than 10.0.6735.0" negate="false" test_ref="oval:org.mitre.oval:tst:554"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:40" version="3" class="vulnerability">
      <metadata>
        <title>IE v5.5,SP2 GetObject File Retrieval</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0023" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0023"/>
        <description>Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to read arbitrary files via malformed requests to the GetObject function, which bypass some of GetObject's security checks.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:35.680-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:17.744-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
        <criterion comment="the version of mshtml.dll is less than 5.50.4913.1100" negate="false" test_ref="oval:org.mitre.oval:tst:3122"/>
        <criterion comment="the patch q316059 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3121"/>
        <criterion comment="the patch q319282 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3120"/>
        <criterion comment="the patch q321232 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3119"/>
        <criterion comment="the patch q323759 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3118"/>
        <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
        <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
        <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3949" version="4" class="vulnerability">
      <metadata>
        <title>IE v5.01, SP3 Plug-in Navigation Address Bar Spoofing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0843" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0843"/>
        <description>Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the "Plug-in Navigation Address Bar Spoofing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-01-20T02:31:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2824. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:48:00.494-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:52:23.599-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:29.050-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:44.755-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:17.653-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3015"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3821.2800" negate="false" test_ref="oval:org.mitre.oval:tst:625"/>
          <criterion comment="the patch kb834707-ie501sp3 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:624"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:393" version="4" class="vulnerability">
      <metadata>
        <title>IE v6.0 Malformed PNG Image File Failure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1185" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1185"/>
        <description>Internet Explorer 5.01 through 6.0 does not properly check certain parameters of a PNG file when opening it, which allows remote attackers to cause a denial of service (crash) by triggering a heap-based buffer overflow using invalid length codes during decompression, aka "Malformed PNG Image File Failure."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-27T05:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-03-09T05:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Changed IE registry test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:35.536-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:17.576-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the version of mshtml.dll is less than 6.0.2722.900" negate="false" test_ref="oval:org.mitre.oval:tst:2884"/>
        <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
        <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
        <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3926" version="5" class="vulnerability">
      <metadata>
        <title>IE6,SP1 Content Advisor Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0555" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0555"/>
        <description>Buffer overflow in the Content Advisor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a crafted Content Advisor file, aka "Content Advisor Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-05-11T05:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-06-23T12:49:00.000-04:00" comment="modified obj:1340 - Set xsi:nil to true on the name entity as we are only concerned with the existance of the key itself.">
              <contributor organization="Centennial Software">Jason Spashett</contributor>
            </modified>
            <status_change date="2006-06-23T12:49:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:23.314-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:46:03.466-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:28.586-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:33.976-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:17.497-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criteria operator="OR" comment="a vulnerable version of mshtml.dll exisits GDR/QFE">
            <criterion comment="machine has followed the GDR update path and mshtml.dll is less than 6.0.2800.1498" negate="false" test_ref="oval:org.mitre.oval:tst:2338"/>
            <criterion comment="machine has followed the QFE update path and mshtml.dll is less than 6.0.2800.1499" negate="false" test_ref="oval:org.mitre.oval:tst:2337"/>
          </criteria>
          <criterion comment="the patch kb890923 is installed (XP Win2K Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2336"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3910" version="5" class="vulnerability">
      <metadata>
        <title>IE5.01,SP4 DHTML Method Heap Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0055" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0055"/>
        <description>Internet Explorer 5.01, 5.5, and 6 does not properly validate buffers when handling certain DHTML methods including the createControlRange Javascript function, which allows remote attackers to execute arbitrary code, aka the "DHTML Method Heap Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-03-23T08:09:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-13T12:15:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-05-04T12:33:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed test to check kb867282.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed ste:2614: set datatype to version.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:54:00.319-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:59:46.182-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:28.356-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:37.613-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:17.354-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3825.700" negate="false" test_ref="oval:org.mitre.oval:tst:994"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:390" version="5" class="vulnerability">
      <metadata>
        <title>IE5.01,SP4 JPEG Image Rendering Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1988" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1988"/>
        <description>Unknown vulnerability in Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to execute arbitrary code via a web site or an HTML e-mail containing a crafted JPEG image that causes memory corruption, aka "JPEG Image Rendering Memory Corruption Vulnerability".</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-23T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-08-25T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed reference to patch kb896727 from criteria.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed ste:2614: set datatype to version.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:54:00.319-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:59:42.263-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:28.153-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:34.839-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:17.280-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3831.1800" negate="false" test_ref="oval:org.mitre.oval:tst:2664"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:39" version="7" class="vulnerability" deprecated="true">
      <metadata>
        <title>DEPRECATED: Windows 2000 IIS HTTP Header Field Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0150" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0150"/>
        <description>Buffer overflow in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to spoof the safety check for HTTP headers and cause a denial of service or execute arbitrary code via HTTP header field values.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected to use a forward slash as the separator in the key." date="2007-05-07T15:59:00.430-04:00">
              <contributor organization="Secure Elements, Inc.">Glenn Strickland</contributor>
            </modified>
            <status_change date="2007-05-07T16:06:10.858-04:00">INTERIM</status_change>
            <status_change date="2007-05-23T15:05:45.654-04:00">ACCEPTED</status_change>
            <modified comment="Multiple corrections and update to POSIX compatibility for ste:2884" date="2010-11-29T16:14:00.692-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-11-29T16:14:38.824-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:56.252-05:00">ACCEPTED</status_change>
            <modified comment="Use def:12124 instead" date="2011-01-20T10:07:34.136-05:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-01-20T10:07:34.136-05:00">DEPRECATED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
          <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
          <criterion comment="the version of w3svc.dll is less than 5.0.2195.5269" negate="false" test_ref="oval:org.mitre.oval:tst:3080"/>
          <criterion comment="Patch Q319733 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3095"/>
          <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
          <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
          <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3079"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="asp.dll mapping exists" negate="false" test_ref="oval:org.mitre.oval:tst:3092"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3881" version="3" class="vulnerability">
      <metadata>
        <title>GDI+ JPEG Parsing Engine Buffer Overflow (Office XP,SP2)</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Office XP SP2</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0200" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0200"/>
        <description>Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-04T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-10-06T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-10-20T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-02-10T12:00:00.000-04:00" comment="modified wft-496 - corrected registry path check">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-02-11T09:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-02T09:01:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Changed criteria to remove test for KB832332.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Microsoft Office XP Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:375"/>
        <criterion comment="the version of mso.dll is less than 10.0.6714.0" negate="false" test_ref="oval:org.mitre.oval:tst:463"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:388" version="4" class="vulnerability">
      <metadata>
        <title>IE v6.0 Cross Domain Verification via Cached Methods Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1254" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1254"/>
        <description>Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model and access information on the local system or in other domains, and possibly execute code, via cached methods and objects, aka "Cross Domain Verification via Cached Methods."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-27T05:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-03-09T05:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Changed IE registry test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:33.521-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:17.188-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the version of mshtml.dll is less than 6.0.2722.900" negate="false" test_ref="oval:org.mitre.oval:tst:2884"/>
        <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
        <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
        <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3851" version="10" class="vulnerability">
      <metadata>
        <title>IE AbusiveParent Vulnerability (Windows 2000)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1319" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1319"/>
        <description>The DHTML Edit Control (dhtmled.ocx) allows remote attackers to inject arbitrary web script into other domains by setting a name for a window, opening a child page whose target is the window with the given name, then injecting the script from the parent into the child using execScript, as demonstrated by "AbusiveParent" in Internet Explorer 6.0.2900.2180.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-02-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2005-02-11T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-03-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-23T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-06-08T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-06-17T12:00:00.000-04:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2005-07-27T10:37:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed obj:823: Removed HKEY_LOCAL_MACHINE\ from the key, as it's specified as the hive.  Implemented by Harvey Rubinovitz." date="2007-01-22T00:37:00.710-05:00">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2007-01-22T00:38:35.456-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:27.616-05:00">ACCEPTED</status_change>
            <modified comment="Corrected and tightened regular expression in ste:2610" date="2010-12-02T11:46:00.307-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-12-02T11:47:27.448-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:55.878-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:44:26.856-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:02:54.880-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:206 - modified vulnerabilities ofÂ MS Visual C++ Â  (winsxs folder checks were modified)" date="2014-04-17T13:09:00.881-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-04-17T13:11:50.268-04:00">INTERIM</status_change>
            <status_change date="2014-05-05T04:00:25.420-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 (sp4 or earlier) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 5 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2790"/>
        </criteria>
        <criterion comment="the version of dhtmled.ocx is less than 6.1.0.9232" negate="false" test_ref="oval:org.mitre.oval:tst:427"/>
        <criterion comment="the patch kb891781 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:1151"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3824" version="5" class="vulnerability">
      <metadata>
        <title>Win2k IP Validation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0048" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0048"/>
        <description>Microsoft Windows XP SP2 and earlier, 2000 SP3 and SP4, Server 2003, and older operating systems allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IP packets with malformed options, aka the "IP Validation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-04-22T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-04-27T12:06:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-11-06T04:13:00.000-04:00" comment="Replaced reference to var:200 with reference to var:201 in obj:588 since tcpip.sys is located in \system32\drivers and not \system32.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:53:55.361-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:44:17.624-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:02:54.172-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="Win2K/XP/2003 service pack 4 (or earlier) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1247"/>
        <criterion comment="the version of Tcpip.sys is less than 5.0.2195.7035" negate="false" test_ref="oval:org.mitre.oval:tst:1012"/>
        <criterion comment="the patch KB893066 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2353"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3810" version="3" class="vulnerability">
      <metadata>
        <title>GDI+ JPEG Parsing Engine Buffer Overflow (Project 2003)</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Project Professional 2003</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0200" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0200"/>
        <description>Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-09-24T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-09-29T12:00:00.000-04:00">DRAFT</status_change>
            <modified date="2004-09-30T12:00:00.000-04:00" comment="Changed affected platforms">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2004-10-20T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-02-10T12:00:00.000-04:00" comment="modified wft-495 - corrected registry path check for .dll file">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-02-11T09:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-02T09:01:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Changed criteria to remove test for KB838344.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Project Professional 2003 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:382"/>
        <criterion comment="the version of gdiplus.dll is less than 6.0.3264.0" negate="false" test_ref="oval:org.mitre.oval:tst:438"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:38" version="7" class="vulnerability">
      <metadata>
        <title>Windows 2000 Group Policy Bypass</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0051" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0051"/>
        <description>Windows 2000 allows local users to prevent the application of new group policy settings by opening Group Policy files with exclusive-read access.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-05-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2005-09-26T10:55:00.000-04:00" comment="modified wft-212 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-31T04:13:00.000-04:00" comment="Replaced reference to obj:1374 with reference to obj:1550 since it references Product\Options and not ProductOptions in the controlset registry key.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:53:55.181-05:00">ACCEPTED</status_change>
            <modified comment="Multiple corrections and update to POSIX compatibility for ste:2884" date="2010-11-29T16:14:00.692-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-11-29T16:14:38.887-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:55.184-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:04.695-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:02:52.916-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 (domain controller) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="this is an NT Server (domain controller)" negate="false" test_ref="oval:org.mitre.oval:tst:3035"/>
        </criteria>
        <criterion comment="the version of srvsvc.dll is less than 5.0.2195.4980" negate="false" test_ref="oval:org.mitre.oval:tst:3034"/>
        <criterion comment="Patch Q318593 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3033"/>
        <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3079"/>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:377" version="2">
      <metadata>
        <title>Microsoft .NET Framework 2.0 Cross-Site Scripting Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft .NET Framework</product>
        </affected>
        <reference ref_id="CVE-2006-3436" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3436" source="CVE"/>
        <description>Cross-site scripting (XSS) vulnerability in Microsoft .NET Framework 2.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving "ASP.NET controls that set the AutoPostBack property to true".</description>
        <oval_repository>
          <dates>
            <submitted date="2006-10-11T05:29:41">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-13T14:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-31T19:35:37.503-05:00">INTERIM</status_change>
            <status_change date="2006-11-21T21:27:46.838-05:00">ACCEPTED</status_change>
            <modified comment="Changed obj:4 to use var:1061 instead of the duplicate var:998" date="2007-07-18T13:46:00.709-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-07-18T13:47:55.255-04:00">INTERIM</status_change>
            <status_change date="2007-08-02T14:47:15.981-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft .NET Framework 2.0 (Original RTM or later) is installed" definition_ref="oval:org.mitre.oval:def:1934"/>
        <criterion comment="the version of Aspnet_filter.dll is less than 2.0.50727.101" test_ref="oval:org.mitre.oval:tst:42"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3752" version="5" class="vulnerability">
      <metadata>
        <title>DHTML Object Memory Corruption Vulnerability (IE6,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0553" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0553"/>
        <description>Race condition in the memory management routines in the DHTML object processor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail, aka "DHTML Object Memory Corruption Vulnerability".</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-05-11T05:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-06-23T12:49:00.000-04:00" comment="modified obj:1340 - Set xsi:nil to true on the name entity as we are only concerned with the existance of the key itself.">
              <contributor organization="Centennial Software">Jason Spashett</contributor>
            </modified>
            <status_change date="2006-06-23T12:49:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:22.554-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:46:05.298-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:27.126-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:35.801-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:16.864-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criteria operator="OR" comment="a vulnerable version of mshtml.dll exisits GDR/QFE">
            <criterion comment="machine has followed the GDR update path and mshtml.dll is less than 6.0.2800.1498" negate="false" test_ref="oval:org.mitre.oval:tst:2338"/>
            <criterion comment="machine has followed the QFE update path and mshtml.dll is less than 6.0.2800.1499" negate="false" test_ref="oval:org.mitre.oval:tst:2337"/>
          </criteria>
          <criterion comment="the patch kb890923 is installed (XP Win2K Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2336"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:375" version="5" class="vulnerability">
      <metadata>
        <title>RIS Writable Path Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5584" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5584"/>
        <description>The Remote Installation Service (RIS) in Microsoft Windows 2000 SP4 uses a TFTP server that allows anonymous access, which allows remote attackers to upload and overwrite arbitrary files to gain privileges on systems that use RIS.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-12-13T08:17:04">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-12-14T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:53:55.046-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:26.933-05:00">ACCEPTED</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.413-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-10-25T16:55:45.610-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:01:14.671-05:00">ACCEPTED</status_change>
            <modified comment="Changed the datatype in ste:181 from INT to STRING and added a new test to check if the patch KB926121 is installed." date="2008-07-30T16:16:00.686-04:00">
              <contributor organization="Secure Elements, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2008-07-30T16:17:35.742-04:00">INTERIM</status_change>
            <status_change date="2008-08-18T04:00:11.206-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:375 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:05:20.938-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:31.336-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
        <criterion comment="TFTP Service is activated." test_ref="oval:org.mitre.oval:tst:177"/>
        <criterion negate="true" comment="The RIS Server has been set to prevent unauthorized access." test_ref="oval:org.mitre.oval:tst:197"/>
        <criterion negate="true" comment="The patch KB926121 is not installed." test_ref="oval:org.mitre.oval:tst:8341"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:374" version="6" class="vulnerability">
      <metadata>
        <title>HTML Help ActiveX Control Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>HTML Help ActiveX Control</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0693" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0693"/>
        <description>Buffer overflow in the HTML Help ActiveX Control (hhctrl.ocx) in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute code via (1) a long parameter to the Alink function, or (2) script containing a long argument to the showHelp function.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if active scripting is enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-07-03T12:56:00.000-04:00" comment="Added negate=true attribute to criteria sub-block to fix conversion error from OVAL 4.2 to OVAL 5.0">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-07-03T12:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:22.284-04:00">ACCEPTED</status_change>
            <modified comment="Fixed regex in ste:2889.  Implemented by Matthew Wojcik." date="2007-03-06T18:19:00.507-05:00">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2007-03-06T18:21:12.667-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:17.857-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:29.833-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:02:52.166-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="the version of hhctrl.ocx is less than 5.2.3669.0" negate="false" test_ref="oval:org.mitre.oval:tst:2676"/>
          <criterion comment="the version of hhsetup.dll is less than 5.2.3644.0" negate="false" test_ref="oval:org.mitre.oval:tst:2675"/>
          <criterion comment="the version of itircl.dll is less than 5.2.3644.0" negate="false" test_ref="oval:org.mitre.oval:tst:2674"/>
          <criterion comment="the version of itss.dll is less than 5.2.3644.0" negate="false" test_ref="oval:org.mitre.oval:tst:2673"/>
          <criterion comment="the patch q323255 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2672"/>
          <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed" negate="true">
            <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
            <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="active scripting is enabled">
            <criteria operator="AND" comment="current user settings are being used and active scripting is enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and active scripting is enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:373" version="6" class="vulnerability">
      <metadata>
        <title>IIS AddHeader Large Header Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0225" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0225"/>
        <description>The ASP function Response.AddHeader in Microsoft Internet Information Server (IIS) 4.0 and 5.0 does not limit memory requests when constructing headers, which allow remote attackers to generate a large header to cause a denial of service (memory consumption) with an ASP page.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2005-03-07T12:00:00.000-04:00" comment="modified wrt-222 - changed pattern match">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-03-09T07:55:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-29T07:59:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Multiple corrections and update to POSIX compatibility for ste:2878" date="2010-11-29T16:13:00.904-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-11-29T16:14:04.835-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:54.861-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:23.801-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:02:51.794-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="File %windir%\system32\inetsrv\asp.dll version is less than 5.0.2195.6672" negate="false" test_ref="oval:org.mitre.oval:tst:2988"/>
        <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
        <criterion comment="SP4 or later Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3073"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:372" version="4" class="vulnerability">
      <metadata>
        <title>IE v6.0,SP1 HijackClick Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0823" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0823"/>
        <description>Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by calling the window.moveBy method, aka HijackClick, a different vulnerability than CVE-2003-1027.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-12-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for specific Windows operating systems.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 sp1 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-01-29T12:00:00.000-04:00" comment="Added Windows XP 64-bit to the list of affected platforms">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:46:00.655-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:26.571-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:38.266-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:16.778-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1276" negate="false" test_ref="oval:org.mitre.oval:tst:2688"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:371" version="3" class="vulnerability">
      <metadata>
        <title>IE v5.5,SP2 HijackClick Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0823" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0823"/>
        <description>Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by calling the window.moveBy method, aka HijackClick, a different vulnerability than CVE-2003-1027.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-12-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for specific Windows operating systems.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.5 sp2 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:38.391-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:16.716-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
          <criterion comment="the version of mshtml.dll is less than 5.50.4934.1600" negate="false" test_ref="oval:org.mitre.oval:tst:2689"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:370" version="4" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP4 HijackClick Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0823" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0823"/>
        <description>Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by calling the window.moveBy method, aka HijackClick, a different vulnerability than CVE-2003-1027.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-12-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for Windows 2000 sp4 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp4 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed ste:2614: set datatype to version.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:54:00.319-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:59:39.916-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:26.325-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:38.334-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:16.646-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3810.1700" negate="false" test_ref="oval:org.mitre.oval:tst:2690"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:369" version="4" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP3 HijackClick Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0823" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0823"/>
        <description>Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by calling the window.moveBy method, aka HijackClick, a different vulnerability than CVE-2003-1027.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-12-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for Windows 2000 sp3 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp3 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2824. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:48:00.494-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:52:27.655-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:26.062-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:37.480-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:16.571-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3015"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3523.1700" negate="false" test_ref="oval:org.mitre.oval:tst:2693"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:368" version="4" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP2 HijackClick Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0823" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0823"/>
        <description>Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by calling the window.moveBy method, aka HijackClick, a different vulnerability than CVE-2003-1027.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-12-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for Windows 2000 sp2 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp2 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2868. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:41:00.387-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:43:10.305-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:25.792-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:37.345-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:16.465-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3063"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3523.1700" negate="false" test_ref="oval:org.mitre.oval:tst:2693"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:367" version="7" class="vulnerability">
      <metadata>
        <title>MS FrontPage Server Extensions Chunked Encoded Request Buffer Overflow (Test 3)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft SharePoint Team Services</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0822" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0822"/>
        <description>Buffer overflow in the debug functionality in fp30reg.dll of Microsoft FrontPage Server Extensions (FPSE) 2000 and 2002 allows remote attackers to execute arbitrary code via a crafted chunked encoded request.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-12-09T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-03-05T12:00:00.000-04:00" comment="Changed the definition to test for fp30reg.dll and fp5areg.dll instead of fp5awel.dll.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2004-09-14T09:52:00.000-04:00" comment="XP SP2 added">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-09-15T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-29T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Multiple corrections and update to POSIX compatibility for ste:2656" date="2010-11-29T16:12:00.873-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-11-29T16:13:01.632-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:54.513-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:21.358-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:02:51.402-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Windows 2000, XP, or 2003 is installed">
            <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
          </criteria>
          <criteria operator="OR" comment="a vulnerable version of fp30reg.dll or fp5areg.dll exists">
            <criterion comment="the version of fp5areg.dll is less than 10.00.4205.0000" negate="false" test_ref="oval:org.mitre.oval:tst:2679"/>
            <criterion comment="the version of fp30reg.dll is less than 10.00.4205.0000" negate="false" test_ref="oval:org.mitre.oval:tst:2678"/>
          </criteria>
          <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="FrontPage Server Extensions 2002 are enabled (NT, 2K, XP)" negate="false" test_ref="oval:org.mitre.oval:tst:2677"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:366" version="8" class="vulnerability">
      <metadata>
        <title>MS FrontPage Server Extensions Chunked Encoded Request Buffer Overflow (Test 2)</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft FrontPage Server Extensions 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0822" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0822"/>
        <description>Buffer overflow in the debug functionality in fp30reg.dll of Microsoft FrontPage Server Extensions (FPSE) 2000 and 2002 allows remote attackers to execute arbitrary code via a crafted chunked encoded request.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-12-09T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-03-05T12:00:00.000-04:00" comment="Changed the definition to test for fp30reg.dll and fp5areg.dll instead of fp5awel.dll.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2004-09-14T09:51:00.000-04:00" comment="XP SP2 added">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-09-15T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-29T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Removed reference to test for nt 4.0 and add reference to nt 4.0 inventory definition." date="2008-02-28T12:48:00.621-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2008-03-03T04:00:46.496-05:00">INTERIM</status_change>
            <status_change date="2008-03-24T04:00:30.912-04:00">ACCEPTED</status_change>
            <modified comment="Multiple corrections and update to POSIX compatibility for ste:2656" date="2010-11-29T16:12:00.873-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-11-29T16:13:02.025-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:54.079-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:22.763-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:02:50.905-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Software section">
          <criteria operator="OR" comment="Windows NT, 2000, or XP is installed">
            <extend_definition comment="Microsoft Windows NT is installed" definition_ref="oval:org.mitre.oval:def:36"/>
            <criterion comment="Windows 2000 is installed" test_ref="oval:org.mitre.oval:tst:3085"/>
            <criterion comment="Windows XP is installed" test_ref="oval:org.mitre.oval:tst:2838"/>
          </criteria>
          <criteria operator="OR" comment="a vulnerable version of fp30reg.dll or fp5areg.dll exists">
            <criterion comment="the version of fp5areg.dll is less than 10.00.4205.0000" test_ref="oval:org.mitre.oval:tst:2679"/>
            <criterion comment="the version of fp30reg.dll is less than 10.00.4205.0000" test_ref="oval:org.mitre.oval:tst:2678"/>
          </criteria>
          <criterion negate="true" comment="Win2K/XP/2003 service pack 2 (or later) is installed" test_ref="oval:org.mitre.oval:tst:2837"/>
        </criteria>
        <criteria operator="AND" comment="Configuration section">
          <criterion comment="FrontPage Server Extensions 2002 are enabled (NT, 2K, XP)" test_ref="oval:org.mitre.oval:tst:2677"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:363" version="4" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP4 Script URLs Cross Domain Zone Restrictions Bypass</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0816" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0816"/>
        <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a file: URL containing Javascript, as demonstrated by NAFfileJPU, (2) using the window.open method to load a file: URL containing Javascript, as demonstrated using WsOpenFileJPU, (3) setting the href property in the base tag for the _search window, as demonstrated using WsBASEjpu, (4) loading the search window into an Iframe, as demonstrated using WsFakeSrc, (5) caching a javascript: URL in the browser history, then accessing that URL in the same frame as the target domain, as demonstrated using WsOpenJpuInHistory, NAFjpuInHistory, BackMyParent, BackMyParent2, and RefBack, aka the "Script URLs Cross Domain" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for Windows 2000 sp4 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp4 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed ste:2614: set datatype to version.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:54:00.319-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:59:41.558-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:25.497-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:37.693-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:16.400-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3810.1700" negate="false" test_ref="oval:org.mitre.oval:tst:2690"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:362" version="4" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP3 Script URLs Cross Domain Zone Restrictions Bypass</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0816" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0816"/>
        <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a file: URL containing Javascript, as demonstrated by NAFfileJPU, (2) using the window.open method to load a file: URL containing Javascript, as demonstrated using WsOpenFileJPU, (3) setting the href property in the base tag for the _search window, as demonstrated using WsBASEjpu, (4) loading the search window into an Iframe, as demonstrated using WsFakeSrc, (5) caching a javascript: URL in the browser history, then accessing that URL in the same frame as the target domain, as demonstrated using WsOpenJpuInHistory, NAFjpuInHistory, BackMyParent, BackMyParent2, and RefBack, aka the "Script URLs Cross Domain" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for Windows 2000 sp3 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp3 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2824. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:48:00.494-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:52:28.053-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:25.208-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:37.018-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:16.335-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3015"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3523.1700" negate="false" test_ref="oval:org.mitre.oval:tst:2693"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:361" version="4" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP2 Script URLs Cross Domain Zone Restrictions Bypass</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0816" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0816"/>
        <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a file: URL containing Javascript, as demonstrated by NAFfileJPU, (2) using the window.open method to load a file: URL containing Javascript, as demonstrated using WsOpenFileJPU, (3) setting the href property in the base tag for the _search window, as demonstrated using WsBASEjpu, (4) loading the search window into an Iframe, as demonstrated using WsFakeSrc, (5) caching a javascript: URL in the browser history, then accessing that URL in the same frame as the target domain, as demonstrated using WsOpenJpuInHistory, NAFjpuInHistory, BackMyParent, BackMyParent2, and RefBack, aka the "Script URLs Cross Domain" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for Windows 2000 sp2 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp2 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2868. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:41:00.387-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:43:09.057-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:24.823-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:36.801-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:16.254-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3063"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3523.1700" negate="false" test_ref="oval:org.mitre.oval:tst:2693"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3586" version="5" class="vulnerability">
      <metadata>
        <title>IE6.0,SP1 Security Zone Restriction Bypass Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0054" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0054"/>
        <description>Internet Explorer 5.01, 5.5, and 6 allows remote attackers to spoof a less restrictive security zone and execute arbitrary code via an HTML page containing URLs that contain hostnames that have been double hex encoded, which are decoded twice to generate a malicious hostname, aka the "URL Decoding Zone Spoofing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-03-23T08:09:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-13T12:15:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-05-04T12:33:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed test to check kb867282.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:46:01.535-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:24.192-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:57.774-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:16.107-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criteria operator="OR" comment="a vulnerable version of mshtml.dll exisits GDR/QFE">
            <criterion comment="machine has followed the GDR update path and mshtml.dll is less than 6.0.2800.1491" negate="false" test_ref="oval:org.mitre.oval:tst:1329"/>
            <criterion comment="machine has followed the QFE update path and mshtml.dll is less than 6.0.2800.1492" negate="false" test_ref="oval:org.mitre.oval:tst:1328"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3585" version="6" class="vulnerability">
      <metadata>
        <title>Web View Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1191" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1191"/>
        <description>The Web View DLL (webvw.dll), as used in Windows Explorer on Windows 2000 systems, does not properly filter an apostrophe ("'") in the author name in a document, which allows attackers to execute arbitrary script via extra attributes when Web View constructs a mailto: link for the preview pane when the user selects the file.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2005-06-01T12:00:00.000-04:00">DRAFT</status_change>
            <modified date="2005-06-17T12:00:00.000-04:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected and tightened regular expression in ste:2610" date="2010-12-02T11:46:00.307-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-12-02T11:47:28.111-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:53.232-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:44:53.976-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:02:50.093-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows 2000 (sp4 or earlier) is installed">
            <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
            <criterion comment="Win2K/XP/2003 service pack 5 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2790"/>
          </criteria>
          <criterion comment="the version of webvw.dll is less than 5.0.3900.7036" negate="false" test_ref="oval:org.mitre.oval:tst:400"/>
          <criterion comment="the patch KB894320 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:399"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Webview is  Enabled" negate="false" test_ref="oval:org.mitre.oval:tst:398"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:357" version="4" class="vulnerability">
      <metadata>
        <title>IE v6.0,SP1 Function Pointer Override Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0815" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0815"/>
        <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arbitrary files by (1) modifying the createTextRange method and using CreateLink, as demonstrated using LinkillerSaveRef, LinkillerJPU, and Linkiller, or (2) modifying the createRange method and using the FIND dialog to select text, as demonstrated using Findeath, aka the "Function Pointer Override Cross Domain" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for specific Windows operating systems.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 sp1 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-01-29T12:00:00.000-04:00" comment="Added Windows XP 64-bit to the list of affected platforms">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:46:03.716-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:23.868-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:52.361-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:16.038-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1276" negate="false" test_ref="oval:org.mitre.oval:tst:2688"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:356" version="3" class="vulnerability">
      <metadata>
        <title>IE v5.5,SP2 Function Pointer Override Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0815" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0815"/>
        <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arbitrary files by (1) modifying the createTextRange method and using CreateLink, as demonstrated using LinkillerSaveRef, LinkillerJPU, and Linkiller, or (2) modifying the createRange method and using the FIND dialog to select text, as demonstrated using Findeath, aka the "Function Pointer Override Cross Domain" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for specific Windows operating systems.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.5 sp2 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:52.425-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:15.970-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
          <criterion comment="the version of mshtml.dll is less than 5.50.4934.1600" negate="false" test_ref="oval:org.mitre.oval:tst:2689"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:353" version="4" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP4 Function Pointer Override Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0815" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0815"/>
        <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arbitrary files by (1) modifying the createTextRange method and using CreateLink, as demonstrated using LinkillerSaveRef, LinkillerJPU, and Linkiller, or (2) modifying the createRange method and using the FIND dialog to select text, as demonstrated using Findeath, aka the "Function Pointer Override Cross Domain" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for Windows 2000 sp4 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of having IE 5.01 sp4 installed.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed ste:2614: set datatype to version.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:54:00.319-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:59:38.416-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:23.325-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:52.612-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:15.902-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3810.1700" negate="false" test_ref="oval:org.mitre.oval:tst:2690"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:352" version="4" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP3 Function Pointer Override Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0815" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0815"/>
        <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arbitrary files by (1) modifying the createTextRange method and using CreateLink, as demonstrated using LinkillerSaveRef, LinkillerJPU, and Linkiller, or (2) modifying the createRange method and using the FIND dialog to select text, as demonstrated using Findeath, aka the "Function Pointer Override Cross Domain" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for Windows 2000 sp3 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of having IE 5.01 sp3 installed.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2824. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:48:00.494-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:52:23.827-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:23.036-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:52.671-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:15.810-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3015"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3523.1700" negate="false" test_ref="oval:org.mitre.oval:tst:2693"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:351" version="4" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP2 Function Pointer Override Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0815" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0815"/>
        <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arbitrary files by (1) modifying the createTextRange method and using CreateLink, as demonstrated using LinkillerSaveRef, LinkillerJPU, and Linkiller, or (2) modifying the createRange method and using the FIND dialog to select text, as demonstrated using Findeath, aka the "Function Pointer Override Cross Domain" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for Windows 2000 sp2 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of having IE 5.01 sp2 installed.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2868. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:41:00.387-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:43:10.987-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:22.761-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:51.937-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:15.727-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3063"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3523.1700" negate="false" test_ref="oval:org.mitre.oval:tst:2693"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:35" version="7" class="vulnerability" deprecated="true">
      <metadata>
        <title>DEPRECATED: Windows 2000 IIS FTP Connection Status Request Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>FTP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0073" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0073"/>
        <description>The FTP service in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows attackers who have established an FTP session to cause a denial of service via a specially crafted status request containing glob characters.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified comment="Corrected to use a forward slash as the separator in the key." date="2007-05-07T15:59:00.528-04:00">
              <contributor organization="Secure Elements, Inc.">Glenn Strickland</contributor>
            </modified>
            <status_change date="2007-05-07T16:04:20.811-04:00">INTERIM</status_change>
            <status_change date="2007-05-23T15:05:44.077-04:00">ACCEPTED</status_change>
            <modified comment="Multiple corrections and update to POSIX compatibility for ste:2884" date="2010-11-29T16:14:00.692-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-11-29T16:14:38.762-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:52.224-05:00">ACCEPTED</status_change>
            <modified comment="Use def:12490 instead" date="2011-01-20T10:00:39.409-05:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-01-20T10:00:39.409-05:00">DEPRECATED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
          <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
          <criterion comment="the version of w3svc.dll is less than 5.0.2195.5269" negate="false" test_ref="oval:org.mitre.oval:tst:3080"/>
          <criterion comment="Patch Q319733 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3095"/>
          <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
          <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
          <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3079"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="FTP Enabled" negate="false" test_ref="oval:org.mitre.oval:tst:3074"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3483" version="10" class="vulnerability">
      <metadata>
        <title>NetBT Name Service Information Access Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>NetBT Name Service</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0661" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0661"/>
        <description>The NetBT Name Service (NBNS) for NetBIOS in Windows NT 4.0, 2000, XP, and Server 2003 may include random memory in a response to a NBNS query, which could allow remote attackers to obtain sensitive information.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-01T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <modified date="2004-07-19T12:00:00.000-04:00" comment="Modifed without comment">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2004-07-20T12:00:00.000-04:00" comment="Modifed without comment">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2004-08-04T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-07-03T12:56:00.000-04:00" comment="Added negate=true attribute to criteria sub-block to fix conversion error from OVAL 4.2 to OVAL 5.0">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-07-03T12:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:21.763-04:00">ACCEPTED</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.448-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-10-25T16:54:43.644-04:00">INTERIM</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.075-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-11-13T12:01:13.476-05:00">ACCEPTED</status_change>
            <modified comment="added tests for windows 2000 and windows server 2003" date="2008-10-24T17:47:00.000-04:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="Added tests" date="2008-11-24T14:59:00.297-05:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2008-11-24T15:04:52.342-05:00">INTERIM</status_change>
            <status_change date="2008-12-15T04:00:16.798-05:00">ACCEPTED</status_change>
            <modified comment="Corrections and update to POSIX compatibility for ste:868" date="2010-11-29T16:09:00.337-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-11-29T16:12:03.526-05:00">INTERIM</status_change>
            <modified comment="Multiple corrections and update to POSIX compatibility for ste:2878" date="2010-11-29T16:13:00.904-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-12-20T04:00:51.578-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:44:54.331-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:02:48.190-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Software section - XP">
          <criterion comment="Windows XP is installed" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criteria negate="true" operator="OR" comment="Patch WindowsXP-KB824105-x86-ENU.exe installed on XP or XP SP1">
            <criterion comment=" Patch WindowsXP-KB824105-x86-ENU.exe installed" test_ref="oval:org.mitre.oval:tst:422"/>
            <criterion comment=" Patch WindowsXP-KB824105-x86-ENU.exe installed on XP SP1" test_ref="oval:org.mitre.oval:tst:421"/>
          </criteria>
          <criteria operator="OR" comment="XP SP1 or Pre SP1 with correct netbt.sys version">
            <criteria operator="AND" comment="Pre Service Pack XP and netbt.sys is less than 5.1.2600.117">
              <criterion comment="the version of netbt.sys is less than 5.1.2600.117" test_ref="oval:org.mitre.oval:tst:420"/>
              <criterion comment="Win2K/XP/2003 service pack 1 (or later) is installed" test_ref="oval:org.mitre.oval:tst:969"/>
            </criteria>
            <criteria operator="AND" comment="XP SP1 and netbt.sys is less than 5.1.2600.1243">
              <criterion comment="the version of netbt.sys is less than 5.1.2600.1243" test_ref="oval:org.mitre.oval:tst:419"/>
              <criterion comment="Win2K/XP/2003/Vista service pack 1 is installed" test_ref="oval:org.mitre.oval:tst:2843"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <criteria operator="OR">
            <criterion comment="Win2K/XP/2003 service pack 3 is installed" test_ref="oval:org.mitre.oval:tst:7814"/>
            <criterion comment="SP4 or later Installed" test_ref="oval:org.mitre.oval:tst:3073"/>
          </criteria>
          <criterion comment="the version of netbt.sys is less than 5.0.2195.6783" test_ref="oval:org.mitre.oval:tst:9512"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
          <criterion comment="the version of netbt.sys is less than 5.2.3790.69" test_ref="oval:org.mitre.oval:tst:9401"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3458" version="5" class="vulnerability">
      <metadata>
        <title>Win2k Blind Connection Reset Attack Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0790" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0790"/>
        <description>Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages, aka the "blind connection-reset attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-04-22T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-04-27T12:06:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-11-06T04:13:00.000-04:00" comment="Replaced reference to var:200 with reference to var:201 in obj:588 since tcpip.sys is located in \system32\drivers and not \system32.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:53:54.175-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:10.546-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:02:47.049-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="Win2K/XP/2003 service pack 4 (or earlier) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1247"/>
        <criterion comment="the version of Tcpip.sys is less than 5.0.2195.7035" negate="false" test_ref="oval:org.mitre.oval:tst:1012"/>
        <criterion comment="the patch KB893066 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2353"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:344" version="4" class="vulnerability">
      <metadata>
        <title>IE v6.0,SP1 ExecCommand Cross Domain Zone Restriction Bypass</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0814" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0814"/>
        <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute Javascript by setting the window's "href" to the malicious Javascript, then calling execCommand("Refresh") to refresh the page, aka BodyRefreshLoadsJPU or the "ExecCommand Cross Domain" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for specific Windows operating systems.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 sp1 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-01-29T12:00:00.000-04:00" comment="Added Windows XP 64-bit to the list of affected platforms">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:46:02.264-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:21.175-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:54.153-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:15.587-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1276" negate="false" test_ref="oval:org.mitre.oval:tst:2688"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:343" version="3" class="vulnerability">
      <metadata>
        <title>IE v5.5,SP2 ExecCommand Cross Domain Zone Restriction Bypass</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0814" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0814"/>
        <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute Javascript by setting the window's "href" to the malicious Javascript, then calling execCommand("Refresh") to refresh the page, aka BodyRefreshLoadsJPU or the "ExecCommand Cross Domain" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for specific Windows operating systems.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.5 sp2 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:54.267-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:15.531-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
          <criterion comment="the version of mshtml.dll is less than 5.50.4934.1600" negate="false" test_ref="oval:org.mitre.oval:tst:2689"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3428" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 Task Scheduler Stack Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Task Scheduler</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0212" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0212"/>
        <description>Stack-based buffer overflow in the Task Scheduler for Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, allows local or remote attackers to execute arbitrary code via a .job file containing long parameters, as demonstrated using Internet Explorer and accessing a .job file on an anonymous share.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-08-04T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="the version of mstask.dll is less than 4.71.2195.6920" negate="false" test_ref="oval:org.mitre.oval:tst:429"/>
        <criterion comment="Patch Windows2000-kb841873-x86-enu.exe Installed" negate="true" test_ref="oval:org.mitre.oval:tst:720"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:342" version="4" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP4 ExecCommand Cross Domain Zone Restriction Bypass</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0814" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0814"/>
        <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute Javascript by setting the window's "href" to the malicious Javascript, then calling execCommand("Refresh") to refresh the page, aka BodyRefreshLoadsJPU or the "ExecCommand Cross Domain" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for Windows 2000 sp4 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp4 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed ste:2614: set datatype to version.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:54:00.319-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:59:38.975-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:20.861-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:54.443-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:15.460-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3810.1700" negate="false" test_ref="oval:org.mitre.oval:tst:2690"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:341" version="4" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP3 ExecCommand Cross Domain Zone Restriction Bypass</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0814" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0814"/>
        <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute Javascript by setting the window's "href" to the malicious Javascript, then calling execCommand("Refresh") to refresh the page, aka BodyRefreshLoadsJPU or the "ExecCommand Cross Domain" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for Windows 2000 sp3 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp3 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2824. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:48:00.494-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:52:26.543-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:20.485-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:54.553-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:15.395-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3015"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3523.1700" negate="false" test_ref="oval:org.mitre.oval:tst:2693"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:340" version="4" class="vulnerability">
      <metadata>
        <title>Windows 2000 ComboBox/ListBox GUI Widget User32.dll Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0659" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0659"/>
        <description>Buffer overflow in a function in User32.dll on Windows NT through Server 2003 allows local users to execute arbitrary code via long (1) LB_DIR messages to ListBox or (2) CB_DIR messages to ComboBox controls in a privileged application.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-16T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-01-27T12:00:00.000-04:00" comment="Added the patch KB891711 (from MS05-002) which supercedes the previous patch">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-01-28T09:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T07:32:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-09-26T12:22:00.000-04:00" comment="modified wft-285 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.059-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-10-25T16:50:29.242-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:01:13.002-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="File %windir%\system32\user32.dll version is less than 5.0.2195.6799" negate="false" test_ref="oval:org.mitre.oval:tst:2691"/>
          <criterion comment="the patch kb824141 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2808"/>
          <criterion comment="the patch kb891711 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2807"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the utility manager Service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2806"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:339" version="3" class="vulnerability">
      <metadata>
        <title>Windows Shell Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference ref_id="CVE-2006-3730" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3730" source="CVE"/>
        <description>Integer overflow in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a 0x7fffffff argument to the setSlice method on a WebViewFolderIcon ActiveX object, which leads to an invalid memory copy.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-10-11T05:29:41">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-13T14:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-31T19:35:36.841-05:00">INTERIM</status_change>
            <status_change date="2006-11-21T21:27:45.994-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:339 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:05:09.969-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:30.591-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win2K,SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="The version of Comctl32.dll is less than 5.81.3900.7109" test_ref="oval:org.mitre.oval:tst:135"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP1">
          <extend_definition comment="Microsoft Windows XP SP1 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          <criterion comment="The version of Comctl32.dll is less than 5.82.2800.1891" test_ref="oval:org.mitre.oval:tst:91"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="The version of Comctl32.dll is less than 5.82.2900.2982" test_ref="oval:org.mitre.oval:tst:54"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP1 (64-bit)">
          <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="The version of Comctl32.dll is less than 5.82.3790.2778" test_ref="oval:org.mitre.oval:tst:58"/>
        </criteria>
        <criteria operator="AND" comment="S03-Gold">
          <extend_definition comment="Microsoft Windows Server 2003 (x86) Gold is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="The version of Comctl32.dll is less than 5.82.3790.583" test_ref="oval:org.mitre.oval:tst:59"/>
        </criteria>
        <criteria operator="AND" comment="S03,SP1">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="The version of Comctl32.dll is less than 5.82.3790.2778" test_ref="oval:org.mitre.oval:tst:58"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3386" version="8" class="vulnerability">
      <metadata>
        <title>Windows 2000 Shell CLSID File Type Spoof Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0420" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0420"/>
        <description>The Windows Shell application in Windows 98, Windows ME, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by spoofing the type of a file via a CLSID specifier in the filename, as demonstrated using Internet Explorer 6.0.2800.1106 on Windows XP.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-04T01:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-10-06T12:57:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-10-20T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-20T07:05:00.000-04:00" comment="Changed criteria to drop explicit test for patch kb839645.  Inclusion resulted in false positives w/o incremental patching.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-04T08:04:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Multiple corrections and update to POSIX compatibility for ste:2656" date="2010-11-29T16:12:00.873-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-11-29T16:12:59.124-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:50.978-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:3386 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:06:22.629-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:02:46.089-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Windows 2000 is installed" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="the version of shell32.dll is less than 5.0.3900.6922" test_ref="oval:org.mitre.oval:tst:436"/>
        <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" test_ref="oval:org.mitre.oval:tst:2837"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:337" version="7" class="vulnerability">
      <metadata>
        <title>TIF Folder Information Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5578" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5578"/>
        <description>Microsoft Internet Explorer 6 and earlier allows remote attackers to read Temporary Internet Files (TIF) and obtain sensitive information via unspecified vectors involving certain drag and drop operations, aka "TIF Folder Information Disclosure Vulnerability," and a different issue than CVE-2006-5577.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-12-13T08:17:04">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-12-14T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:53:53.907-05:00">INTERIM</status_change>
            <modified comment="Added an anchor to the regex used to check for Internet Explorer 6." date="2007-01-11T20:38:00.950-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-20T13:40:19.295-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:2185 - Anchored regular expression" date="2011-02-22T12:51:00.261-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:52:35.842-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:00:49.646-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:48.032-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:15.228-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:337 - Addressed validation errors and duplicate extended definitions" date="2015-07-13T20:21:00.869-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:25:22.222-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:01:54.427-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Server 2003-Gold">
          <extend_definition comment="Microsoft Windows Server 2003 (x86) Gold is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.605" test_ref="oval:org.mitre.oval:tst:92"/>
        </criteria>
        <criteria comment="XP,SP1 (64-bit) and Server 2003, SP1">
          <criteria operator="OR" comment="Windows XP (64-bit,SP1) or Server 2003 (SP1) is installed">
            <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2817" test_ref="oval:org.mitre.oval:tst:90"/>
        </criteria>
        <criteria comment="IE 6 on Windows XP,SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3020" test_ref="oval:org.mitre.oval:tst:132"/>
        </criteria>
        <criteria comment="IE 6 on Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1586" test_ref="oval:org.mitre.oval:tst:89"/>
        </criteria>
        <criteria comment="IE 5.01,SP4 on Win2k,SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3846.2300" test_ref="oval:org.mitre.oval:tst:88"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:335" version="4" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP2 ExecCommand Cross Domain Zone Restriction Bypass</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0814" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0814"/>
        <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute Javascript by setting the window's "href" to the malicious Javascript, then calling execCommand("Refresh") to refresh the page, aka BodyRefreshLoadsJPU or the "ExecCommand Cross Domain" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for Windows 2000 sp2 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp2 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2868. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:41:00.387-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:43:09.301-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:18.820-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:47.864-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:15.131-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3063"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3523.1700" negate="false" test_ref="oval:org.mitre.oval:tst:2693"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:334" version="6" class="vulnerability">
      <metadata>
        <title>Windows NNTP Memory Leak</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Network News Transport Protocol (NNTP)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0543" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0543"/>
        <description>Memory leak in NNTP service in Windows NT 4.0 and Windows 2000 allows remote attackers to cause a denial of service (memory exhaustion) via a large number of malformed posts.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-16T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Multiple corrections and update to POSIX compatibility for ste:2884" date="2010-11-29T16:14:00.692-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-11-29T16:14:38.975-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:50.304-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:44:38.356-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:02:45.224-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3079"/>
          <criterion comment="the version of nntpsvc.dll is less than 5.0.2195.3881" negate="false" test_ref="oval:org.mitre.oval:tst:2695"/>
          <criterion comment="Patch Q303984 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2694"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the NNTP service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2757"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:333" version="3" class="vulnerability">
      <metadata>
        <title>IE v5.5 Domain Restriction Bypass Cross-Frame Scripting</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1217" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1217"/>
        <description>Cross-Frame scripting vulnerability in the WebBrowser control as used in Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code, read arbitrary files, or conduct other unauthorized activities via script that accesses the Document property, which bypasses &lt;frame> and &lt;iframe> domain restrictions.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-27T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:47.751-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:15.073-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Internet Explorer 5.5 Installed">
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3078"/>
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3077"/>
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3076"/>
          <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
        </criteria>
        <criterion comment="the version of mshtml.dll is less than 5.50.4922.900" negate="false" test_ref="oval:org.mitre.oval:tst:2786"/>
        <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
        <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
        <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3320" version="4" class="vulnerability">
      <metadata>
        <title>GDI+ JPEG Parsing Engine Buffer Overflow Microsoft Office Visio Pro 2003</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Office Visio Professional 2003</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0200" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0200"/>
        <description>Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-09-27T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-09-29T12:00:00.000-04:00">DRAFT</status_change>
            <modified date="2004-09-30T12:00:00.000-04:00" comment="Changed affected platforms">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2004-10-20T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-02-10T12:00:00.000-04:00" comment="modified wft-495 - corrected registry path check for .dll file">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-02-11T09:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-02T09:01:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Changed criteria to remove test for KB838345.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Altered to leverage new inventory def:1450" date="2007-06-15T14:06:00.373-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-06-15T14:06:36.408-04:00">INTERIM</status_change>
            <status_change date="2007-07-03T14:05:59.508-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <extend_definition definition_ref="oval:org.mitre.oval:def:1450"/>
        <criterion comment="the version of gdiplus.dll is less than 6.0.3264.0" negate="false" test_ref="oval:org.mitre.oval:tst:438"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1450" version="7" class="inventory">
      <metadata>
        <title>Microsoft Office Visio 2003 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Office Visio 2003</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:visio:2003"/>
        <description>The application Microsoft Office Visio 2003 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-06-15T11:00:31-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-06-15T15:20:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-07-03T14:05:55.207-04:00">INTERIM</status_change>
            <status_change date="2007-07-18T15:57:49.776-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:58.837-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:58.837-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:02:47.424-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1450 - products added to inventories" date="2015-04-17T09:41:00.607-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-04-17T09:42:54.635-04:00">INTERIM</status_change>
            <status_change date="2015-05-04T04:00:07.748-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:439 - Added check for standard version in MS Visio 2003 inventory" date="2015-07-29T13:09:00.256-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-29T13:11:51.017-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:06.111-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Microsoft Office Visio 2003 is Installed" test_ref="oval:org.mitre.oval:tst:439"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3318" version="5" class="vulnerability">
      <metadata>
        <title>IE6,SP1 Channel Definition Format Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0056" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0056"/>
        <description>Internet Explorer 5.01, 5.5, and 6 does not properly validate certain URLs in Channel Definition Format (CDF) files, which allows remote attackers to obtain sensitive information or execute arbitrary code, aka the "Channel Definition Format (CDF) Cross Domain Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-03-23T08:09:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-13T12:15:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-05-04T12:33:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed test to check kb867282.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:45:59.798-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:18.542-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:56.020-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:14.995-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criteria operator="OR" comment="a vulnerable version of mshtml.dll exisits GDR/QFE">
            <criterion comment="machine has followed the GDR update path and mshtml.dll is less than 6.0.2800.1491" negate="false" test_ref="oval:org.mitre.oval:tst:1329"/>
            <criterion comment="machine has followed the QFE update path and mshtml.dll is less than 6.0.2800.1492" negate="false" test_ref="oval:org.mitre.oval:tst:1328"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:322" version="3" class="vulnerability">
      <metadata>
        <title>IE v5.5,SP2 Bitmap Integer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0566" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0566"/>
        <description>Integer overflow in imgbmp.cxx for Windows 2000 allows remote attackers to execute arbitrary code via a BMP image with a large bfOffBits value.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-08-02T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:49.661-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:14.886-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
        <criterion comment="the version of mshtml.dll is less than 5.50.4943.400" negate="false" test_ref="oval:org.mitre.oval:tst:2762"/>
        <criterion comment="the patch kb832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2802"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3216" version="8" class="vulnerability">
      <metadata>
        <title>Animated Cursor Denial of Service (Windows 2000)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows Animated Cursor</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1305" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1305"/>
        <description>The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allow remote attackers to cause a denial of service via (1) the frame number set to zero, which causes an invalid memory address to be used and leads to a kernel crash, or (2) the rate number set to zero, which leads to resource exhaustion and hang.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-20T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-17T12:00:00.000-04:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2005-06-22T12:35:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">ACCEPTED</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.059-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-10-25T16:50:28.219-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:01:11.844-05:00">ACCEPTED</status_change>
            <modified comment="Corrected and tightened regular expression in ste:2610" date="2010-12-02T11:46:00.307-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-12-02T11:47:27.352-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:49.090-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:46:24.678-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:02:43.224-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 (sp4 or earlier) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 5 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2790"/>
        </criteria>
        <criterion comment="the version of user32.dll is less than 5.0.2195.7017" negate="false" test_ref="oval:org.mitre.oval:tst:446"/>
        <criterion comment="the patch kb891711 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2807"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:32" version="3" class="vulnerability">
      <metadata>
        <title>IE v6.0 Forced Script Execution</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0026" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0026"/>
        <description>Internet Explorer 5.5 and 6.0 allows remote attackers to bypass restrictions for executing scripts via an object that processes asynchronous events after the initial security checks have been made.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T05:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Changed IE registry test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:33.629-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:14.826-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the version of mshtml.dll is less than 6.0.2713.1100" negate="false" test_ref="oval:org.mitre.oval:tst:3091"/>
        <criterion comment="the patch q316059 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3121"/>
        <criterion comment="the patch q319282 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3120"/>
        <criterion comment="the patch q321232 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3119"/>
        <criterion comment="the patch q323759 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3118"/>
        <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
        <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
        <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:318" version="4" class="vulnerability">
      <metadata>
        <title>Folder GUID Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference ref_id="CVE-2006-3281" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3281" source="CVE"/>
        <description>Microsoft Internet Explorer 6.0 does not properly handle Drag and Drop events, which allows remote user-assisted attackers to execute arbitrary code via a link to an SMB file share with a filename that contains encoded ..\ (%2e%2e%5c) sequences and whose extension contains the CLSID Key identifier for HTML Applications (HTA), aka "Folder GUID Code Execution Vulnerability."  NOTE: directory traversal sequences were used in the original exploit, although their role is not clear.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:20.777-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:38.214-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:318 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:06:47.319-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:30.208-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win2K,SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="The version of shell32.dll is less than 5.0.3900.7105." test_ref="oval:org.mitre.oval:tst:129"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP1">
          <extend_definition comment="Microsoft Windows XP SP1 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          <criterion comment="The version of shell32.dll is less than 6.0.2800.1873." test_ref="oval:org.mitre.oval:tst:199"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="The version of shell32.dll is less than 6.0.2900.2951." test_ref="oval:org.mitre.oval:tst:160"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP1 (64-bit)">
          <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="The version of shell32.dll is less than 6.0.3790.2746." test_ref="oval:org.mitre.oval:tst:12"/>
        </criteria>
        <criteria operator="AND" comment="S03-Gold">
          <extend_definition comment="Microsoft Windows Server 2003 (x86) Gold is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="The version of shell32.dll is less than 6.0.3790.559." test_ref="oval:org.mitre.oval:tst:14"/>
        </criteria>
        <criteria operator="AND" comment="S03,SP1">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="The version of shell32.dll is less than 6.0.3790.2746." test_ref="oval:org.mitre.oval:tst:12"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:316" version="3" class="vulnerability">
      <metadata>
        <title>MS SQL Server Bulk Insert Procedure Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft SQL Server 2000</product>
          <product>Microsoft SQL Server 2000 Desktop Engine (WMSDE)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0641" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0641"/>
        <description>Buffer overflow in bulk insert procedure of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows attackers with database administration privileges to execute arbitrary code via a long filename in the BULK INSERT query.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
            </submitted>
            <modified date="2005-04-08T10:31:00.000-04:00" comment="modified wft-237 - literal string corrected">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:31:00.000-04:00" comment="modified wft-65 - Corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:31:00.000-04:00" comment="modified wft-66 - corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:31:00.000-04:00" comment="modified wft-67 - Corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:31:00.000-04:00" comment="modified wft-68 - Corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:32:00.000-04:00" comment="modified wft-69 - corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:33:00.000-04:00" comment="modified wft-278 - wft-278 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:34:00.000-04:00" comment="modified wft-58 - wft-58 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-11T08:48:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:316 - SQL Server 2000 has been replaced by Microsoft SQL Server 2000" date="2014-06-02T14:52:00.465-04:00">
              <contributor organization="McAfee, Inc.">Jerome Athias</contributor>
            </modified>
            <status_change date="2014-06-02T14:54:19.939-04:00">INTERIM</status_change>
            <status_change date="2014-06-23T04:07:47.100-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="SQL Server 2000 is installed" test_ref="oval:org.mitre.oval:tst:2977"/>
        <criterion comment="the version of sqlservr.exe is less than 2000.80.650.0" test_ref="oval:org.mitre.oval:tst:2718"/>
        <criterion comment="the version of odsole70.dll is less than 2000.80.606.0" test_ref="oval:org.mitre.oval:tst:2925"/>
        <criterion comment="the version of xpqueue.dll is less than 2000.80.606.0" test_ref="oval:org.mitre.oval:tst:2924"/>
        <criterion comment="the version of xprepl.dll is less than 2000.80.606.0" test_ref="oval:org.mitre.oval:tst:2923"/>
        <criterion comment="the version of xplog70.dll is less than 2000.80.606.0" test_ref="oval:org.mitre.oval:tst:2922"/>
        <criterion comment="the version of xpweb70.dll is less than 2000.80.606.0" test_ref="oval:org.mitre.oval:tst:2921"/>
        <criterion comment="the version of xpstar.dll is less than 2000.80.628.0" test_ref="oval:org.mitre.oval:tst:2920"/>
        <criterion comment="the version of impprov.dll is less than 2000.80.650.0" test_ref="oval:org.mitre.oval:tst:2704"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3145" version="2" class="vulnerability">
      <metadata>
        <title>Windows 2000 Kernel Debugger-based Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0112" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0112"/>
        <description>Buffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <modified date="2004-07-14T12:00:00.000-04:00" comment="Changed to DRAFT">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-08-04T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-06-08T03:17:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-29T06:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="The version of Ntoskrnl.exe is less than 5.0.2195.6159" negate="false" test_ref="oval:org.mitre.oval:tst:449"/>
        <criterion comment="the patch Q811493 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2885"/>
        <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:313" version="7" class="vulnerability">
      <metadata>
        <title>TIF Folder Information Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5577" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5577"/>
        <description>Microsoft Internet Explorer 6 and earlier allows remote attackers to obtain sensitive information via unspecified uses of the OBJECT HTML tag, which discloses the absolute path of the corresponding TIF folder, aka "TIF Folder Information Disclosure Vulnerability," and a different issue than CVE-2006-5578.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-12-13T08:17:04">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-12-14T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:53:53.175-05:00">INTERIM</status_change>
            <modified comment="Added an anchor to the regex used to check for Internet Explorer 6." date="2007-01-11T20:38:00.950-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-20T13:40:16.554-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:2185 - Anchored regular expression" date="2011-02-22T12:51:00.261-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:52:33.058-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:00:49.142-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:58.351-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:14.420-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:132 - Addressed validation errors and duplicate extended definitions" date="2015-07-13T20:21:00.869-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:25:23.103-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:01:54.188-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Server 2003-Gold">
          <extend_definition comment="Microsoft Windows Server 2003 (x86) Gold is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.605" test_ref="oval:org.mitre.oval:tst:92"/>
        </criteria>
        <criteria comment="XP,SP1 (64-bit) and Server 2003, SP1">
          <criteria operator="OR" comment="Windows XP (64-bit,SP1) or Server 2003 (SP1) is installed">
            <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2817" test_ref="oval:org.mitre.oval:tst:90"/>
        </criteria>
        <criteria comment="IE 6 on Windows XP,SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3020" test_ref="oval:org.mitre.oval:tst:132"/>
        </criteria>
        <criteria comment="IE 6 on Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1586" test_ref="oval:org.mitre.oval:tst:89"/>
        </criteria>
        <criteria comment="IE 5.01,SP4 on Win2k,SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3846.2300" test_ref="oval:org.mitre.oval:tst:88"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3120" version="8" class="vulnerability">
      <metadata>
        <title>Windows 2000 Unchecked Buffer in NetDDE (Test 1)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>NetDDE</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0206" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0206"/>
        <description>Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application that involves an "unchecked buffer," possibly a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-13T04:17:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.630-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-10-25T16:52:11.329-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:01:11.651-05:00">ACCEPTED</status_change>
            <modified comment="Corrected tst:452 to refer to obj:260" date="2010-11-22T18:00:00.000-05:00">
              <contributor organization="Critical Watch">Nelson Bunker</contributor>
            </modified>
            <status_change date="2010-11-22T18:00:00.000-05:00">INTERIM</status_change>
            <modified comment="Corrected and tightened regular expression in ste:2610" date="2010-12-02T11:46:00.307-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-12-20T04:00:48.688-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:44:24.682-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:02:42.779-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 (sp5 or earlier) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 5 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2790"/>
        </criteria>
        <criterion comment="the version of netdde.exe is less than 5.0.2195.6952" negate="false" test_ref="oval:org.mitre.oval:tst:453"/>
        <criterion comment="the version of nddenb32.dll is less than 5.0.2195.6922" negate="false" test_ref="oval:org.mitre.oval:tst:452"/>
        <criterion comment="the patch KB841533 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:682"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3082" version="3" class="vulnerability">
      <metadata>
        <title>GDI+ JPEG Parsing Engine Buffer Overflow (Visio Pro 2002)</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Office Visio Professional 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0200" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0200"/>
        <description>Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-09-27T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-09-29T12:00:00.000-04:00">DRAFT</status_change>
            <modified date="2004-09-30T12:00:00.000-04:00" comment="Changed affected platforms">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2004-10-20T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-02-10T12:00:00.000-04:00" comment="modified wft-496 - corrected registry path check">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-02-11T09:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-02T09:01:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Changed criteria to remove test for KB831932.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Visio Professional 2002 with service pack 2" negate="false" test_ref="oval:org.mitre.oval:tst:481"/>
        <criterion comment="the version of mso.dll is less than 10.0.6714.0" negate="false" test_ref="oval:org.mitre.oval:tst:463"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:308" version="7" class="vulnerability">
      <metadata>
        <title>MS FrontPage Server Extensions SmartHTML Denial of Service (Test 1)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft FrontPage Server Extensions 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0824" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0824"/>
        <description>Unknown vulnerability in the SmartHTML interpreter (shtml.dll) in Microsoft FrontPage Server Extensions 2000 and 2002, and Microsoft SharePoint Team Services 2002, allows remote attackers to cause a denial of service (response failure) via a certain request.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-12-09T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2004-01-14T12:00:00.000-04:00" comment="Changed the definition to look at the file shtml.dll instead of fp4awel.dll.  It was determined that this is where the vulnerability (a buffer overflow) actually existed.  Also added the configuration test saying you are vulnerable if the SmartHTML interpreter is enabled.">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T10:51:00.000-04:00" comment="modified wft-12 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed regex in ste:2889.  Implemented by Matthew Wojcik." date="2007-03-06T18:19:00.507-05:00">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2007-03-06T18:21:08.128-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:15.842-04:00">ACCEPTED</status_change>
            <modified comment="Corrected to use a forward slash as the separator in the key." date="2007-05-07T15:59:00.964-04:00">
              <contributor organization="Secure Elements, Inc.">Glenn Strickland</contributor>
            </modified>
            <status_change date="2007-05-07T16:05:38.149-04:00">INTERIM</status_change>
            <status_change date="2007-05-23T15:05:43.156-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:44:59.318-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:02:41.914-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows 2000 (sp3 or earlier) is installed">
            <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
            <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3084"/>
          </criteria>
          <criterion comment="the version of shtml.dll is less than 4.00.02.7523" negate="false" test_ref="oval:org.mitre.oval:tst:2708"/>
          <criterion comment="the patch q810217 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2707"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="FrontPage Server Extensions 2000 are enabled (2K, XP)" negate="false" test_ref="oval:org.mitre.oval:tst:2706"/>
          <criterion comment="SmartHTML interpreter is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2705"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:306" version="4" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP3 Bitmap Integer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0566" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0566"/>
        <description>Integer overflow in imgbmp.cxx for Windows 2000 allows remote attackers to execute arbitrary code via a BMP image with a large bfOffBits value.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-08-02T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2824. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:48:00.494-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:52:27.505-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:15.839-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:59.863-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:14.169-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3015"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3532.300" negate="false" test_ref="oval:org.mitre.oval:tst:2803"/>
        <criterion comment="the patch kb832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2802"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3038" version="3" class="vulnerability">
      <metadata>
        <title>GDI+ JPEG Parsing Engine Buffer Overflow (Project 2002,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Project Professional 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0200" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0200"/>
        <description>Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-09-27T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-09-29T12:00:00.000-04:00">DRAFT</status_change>
            <modified date="2004-09-30T12:00:00.000-04:00" comment="Changed affected platforms">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2004-10-20T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-02-10T12:00:00.000-04:00" comment="modified wft-496 - corrected registry path check">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-02-11T09:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-02T09:01:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Changed criteria to remove test for KB831931.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Project Professional 2002 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:555"/>
        <criterion comment="the version of mso.dll is less than 10.0.6714.0" negate="false" test_ref="oval:org.mitre.oval:tst:463"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:303" version="6" class="vulnerability">
      <metadata>
        <title>SQL Server LPC Port Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft SQL Server 2000</product>
          <product>Microsoft SQL Server 2000 Desktop Engine (WMSDE)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0232" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0232"/>
        <description>Microsoft SQL Server 7, 2000, and MSDE allows local users to execute arbitrary code via a certain request to the Local Procedure Calls (LPC) port that leads to a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
            </submitted>
            <modified date="2005-01-14T12:00:00.000-04:00" comment="modified wft-55 - Added &quot;80&quot; to the registry component. So that new component value is HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft SQL Server\80\SharedCode. This key specifes the location of the  file that should be tested.">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2005-01-20T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-04-08T10:31:00.000-04:00" comment="modified wft-72 - corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:32:00.000-04:00" comment="modified wft-70 - Corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:41:00.000-04:00" comment="modified wft-73 - Corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:51:00.000-04:00" comment="modified wft-78 - wft-78 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T11:01:00.000-04:00" comment="modified wft-79 - wft-79 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T11:31:00.000-04:00" comment="modified wft-51 - wft-51 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T11:32:00.000-04:00" comment="modified wft-52 - wft-52 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T11:33:00.000-04:00" comment="modified wft-53 - wft-53 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T11:34:00.000-04:00" comment="modified wft-54 - wft-54 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T11:51:00.000-04:00" comment="modified wft-60 - wft-60 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-11T08:48:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-27T01:23:00.000-04:00" comment="modified wft-70 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-09-27T01:24:00.000-04:00" comment="modified wft-72 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-09-27T01:25:00.000-04:00" comment="modified wft-73 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed obj:1560, missing first character due to conversion error.  Was sgprox.dll, now msgprox.dll.  Also fixed comment on var:257, used by obj:1560." date="2007-01-22T18:59:00.461-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-01-22T18:57:30.998-05:00">INTERIM</status_change>
            <modified comment="Fixed obj:1559, missing first character due to conversion error.  Was eplrec.dll, now replrec.dll." date="2007-01-22T19:00:00.302-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <modified comment="Fixed obj:1557, missing first character in filename due to conversion error.  Was qlvdi.dll, now sqlvdi.dll." date="2007-01-22T19:08:00.006-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <modified comment="Fixed obj:1589, missing first character in filename due to conversion error.  Was eplprov.dll, now replprov.dll." date="2007-01-22T19:20:00.817-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-20T13:40:15.454-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:303 - SQL Server 2000 has been replaced by Microsoft SQL Server 2000" date="2014-06-02T14:54:00.396-04:00">
              <contributor organization="McAfee, Inc.">Jerome Athias</contributor>
            </modified>
            <status_change date="2014-06-02T14:56:26.858-04:00">INTERIM</status_change>
            <status_change date="2014-06-23T04:07:46.845-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="SQL Server 2000 is installed" test_ref="oval:org.mitre.oval:tst:2977"/>
        <criterion comment="File console.exe version3 is less than 2000.80.818.0" test_ref="oval:org.mitre.oval:tst:2780"/>
        <criterion comment="the version of dbmslpcn.dll is less than 2000.80.818.0" test_ref="oval:org.mitre.oval:tst:2713"/>
        <criterion comment="File sqlmap70.dll version3 is less than 2000.80.811.0" test_ref="oval:org.mitre.oval:tst:2778"/>
        <criterion comment="File sqlrepss.dll version3 is less than 2000.80.765.0" test_ref="oval:org.mitre.oval:tst:2777"/>
        <criterion comment="the version of sqlservr.exe is less than 2000.80.818.0" test_ref="oval:org.mitre.oval:tst:2776"/>
        <criterion comment="the version of ssmslpcn.dll is less than 2000.80.818.0" test_ref="oval:org.mitre.oval:tst:2775"/>
        <criterion comment="the version of ssnetlib.dll is less than 2000.80.818.0" test_ref="oval:org.mitre.oval:tst:2774"/>
        <criterion comment="the version of ssnmpn70.dll is less than 2000.80.818.0" test_ref="oval:org.mitre.oval:tst:2773"/>
        <criterion comment="the version of ums.dll is less than 2000.80.816.0" test_ref="oval:org.mitre.oval:tst:2772"/>
        <criterion comment="the version of odsole70.dll is less than 2000.80.800.0" test_ref="oval:org.mitre.oval:tst:2771"/>
        <criterion comment="the version of xpweb70.dll is less than 2000.80.778.0" test_ref="oval:org.mitre.oval:tst:2770"/>
        <criterion comment="the version of msgprox.dll is less than 2000.80.765.0" test_ref="oval:org.mitre.oval:tst:2712"/>
        <criterion comment="the version of replprov.dll is less than 2000.80.798.0" test_ref="oval:org.mitre.oval:tst:2768"/>
        <criterion comment="the version of replrec.dll is less than 2000.80.765.0" test_ref="oval:org.mitre.oval:tst:2711"/>
        <criterion comment="the version of sqlvdi.dll is less than 2000.80.765.0" test_ref="oval:org.mitre.oval:tst:2710"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3006" version="7" class="vulnerability">
      <metadata>
        <title>IE5.01,SP3 Drag-and-Drop Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0053" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0053"/>
        <description>Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the "Drag-and-Drop Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-03-23T08:09:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-13T12:15:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-05-04T12:33:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed test to check kb867282.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2824. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:48:00.494-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:52:28.437-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:15.222-05:00">ACCEPTED</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.795-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-10-25T16:47:48.480-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:01:10.892-05:00">ACCEPTED</status_change>
            <modified comment="Fix for regular expression" date="2010-01-13T14:40:00.667-05:00">
              <contributor organization="The MITRE Corporation">Dan Haynes</contributor>
            </modified>
            <status_change date="2010-01-13T14:41:05.146-05:00">INTERIM</status_change>
            <status_change date="2010-02-01T04:00:07.585-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:40.018-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:14.088-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3015"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3528.700" negate="false" test_ref="oval:org.mitre.oval:tst:749"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="Check for Drag&amp;Drop enabled and the patch kb834707(wildcard*)  missing">
            <criterion comment="Drag-and-Drop disabled when set to 3" negate="true" test_ref="oval:org.mitre.oval:tst:1316"/>
            <criterion comment="the patch kb834707(wildcard*) is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:977"/>
          </criteria>
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:30" version="6" class="vulnerability">
      <metadata>
        <title>Microsoft SMTP Malformed BDAT Request Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>SMTP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0055" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0055"/>
        <description>SMTP service in Microsoft Windows 2000, Windows XP Professional, and Exchange 2000 allows remote attackers to cause a denial of service via a command with a malformed data transfer (BDAT) request.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-05-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2004-03-30T12:00:00.000-04:00" comment="Changed the registry key in question for the SMTP enabled check to SMTPSVC from SMTP.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified comment="Multiple corrections and update to POSIX compatibility for ste:2884" date="2010-11-29T16:14:00.692-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-11-29T16:14:39.071-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:48.093-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:06.786-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:02:41.296-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="File %windir%\system32\inetsrv\smtpsvc.dll version is less than 5.0.2195.4905" negate="false" test_ref="oval:org.mitre.oval:tst:3056"/>
          <criterion comment="Patch Q313450" negate="true" test_ref="oval:org.mitre.oval:tst:3055"/>
          <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3079"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="SMTP Enabled" negate="false" test_ref="oval:org.mitre.oval:tst:3054"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3" version="3" class="vulnerability">
      <metadata>
        <title>SMB Information Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference ref_id="CVE-2006-1315" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1315" source="CVE"/>
        <description>The Server Service (SRV.SYS driver) in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 up to SP1, and other products, allows remote attackers to obtain sensitive information via crafted requests that leak information in SMB buffers, which are not properly initialized, aka "SMB Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-27T12:29:20.234-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:37.531-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:3 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:05:34.146-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:29.780-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win2K,SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of srv.sys is less than 5.0.2195.7087" test_ref="oval:org.mitre.oval:tst:64"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP1">
          <extend_definition comment="Microsoft Windows XP SP1 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          <criterion comment="the version of srv.sys is less than 5.1.2600.1832" test_ref="oval:org.mitre.oval:tst:23"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of srv.sys is less than 5.1.2600.2893" test_ref="oval:org.mitre.oval:tst:127"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP1 (64-bit)">
          <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="the version of srv.sys is less than 5.2.3790.2691" test_ref="oval:org.mitre.oval:tst:161"/>
        </criteria>
        <criteria operator="AND" comment="S03-Gold">
          <extend_definition comment="Microsoft Windows Server 2003 (x86) Gold is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="the version of srv.sys is less than 5.2.3790.526" test_ref="oval:org.mitre.oval:tst:97"/>
        </criteria>
        <criteria operator="AND" comment="S03,SP1">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of srv.sys is less than 5.2.3790.2691" test_ref="oval:org.mitre.oval:tst:161"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:299" version="6" class="vulnerability">
      <metadata>
        <title>SQL Server Named Pipe Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft SQL Server 2000</product>
          <product>Microsoft SQL Server 2000 Desktop Engine (WMSDE)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0231" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0231"/>
        <description>Microsoft SQL Server 7, 2000, and MSDE allows local or remote authenticated users to cause a denial of service (crash or hang) via a long request to a named pipe.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
            </submitted>
            <modified date="2005-01-14T12:00:00.000-04:00" comment="modified wft-55 - Added &quot;80&quot; to the registry component. So that new component value is HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft SQL Server\80\SharedCode. This key specifes the location of the  file that should be tested.">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2005-01-20T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-04-08T10:31:00.000-04:00" comment="modified wft-72 - corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:32:00.000-04:00" comment="modified wft-70 - Corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:33:00.000-04:00" comment="modified wft-73 - Corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:34:00.000-04:00" comment="modified wft-78 - wft-78 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:35:00.000-04:00" comment="modified wft-79 - wft-79 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:36:00.000-04:00" comment="modified wft-51 - wft-51 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:37:00.000-04:00" comment="modified wft-52 - wft-52 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:38:00.000-04:00" comment="modified wft-53 - wft-53 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:39:00.000-04:00" comment="modified wft-54 - wft-54 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:40:00.000-04:00" comment="modified wft-60 - wft-60 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-11T08:48:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-27T01:23:00.000-04:00" comment="modified wft-70 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-09-27T01:24:00.000-04:00" comment="modified wft-72 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-09-27T01:25:00.000-04:00" comment="modified wft-73 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed obj:1560, missing first character due to conversion error.  Was sgprox.dll, now msgprox.dll.  Also fixed comment on var:257, used by obj:1560." date="2007-01-22T18:59:00.461-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-01-22T18:57:30.571-05:00">INTERIM</status_change>
            <modified comment="Fixed obj:1559, missing first character due to conversion error.  Was eplrec.dll, now replrec.dll." date="2007-01-22T19:00:00.302-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <modified comment="Fixed obj:1557, missing first character in filename due to conversion error.  Was qlvdi.dll, now sqlvdi.dll." date="2007-01-22T19:08:00.006-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <modified comment="Fixed obj:1589, missing first character in filename due to conversion error.  Was eplprov.dll, now replprov.dll." date="2007-01-22T19:20:00.817-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-20T13:40:14.695-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:299 - SQL Server 2000 has been replaced by Microsoft SQL Server 2000" date="2014-06-02T14:56:00.745-04:00">
              <contributor organization="McAfee, Inc.">Jerome Athias</contributor>
            </modified>
            <status_change date="2014-06-02T14:57:39.214-04:00">INTERIM</status_change>
            <status_change date="2014-06-23T04:07:46.560-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="SQL Server 2000 is installed" test_ref="oval:org.mitre.oval:tst:2977"/>
        <criterion comment="File console.exe version3 is less than 2000.80.818.0" test_ref="oval:org.mitre.oval:tst:2780"/>
        <criterion comment="the version of dbmslpcn.dll is less than 2000.80.818.0" test_ref="oval:org.mitre.oval:tst:2713"/>
        <criterion comment="File sqlmap70.dll version3 is less than 2000.80.811.0" test_ref="oval:org.mitre.oval:tst:2778"/>
        <criterion comment="File sqlrepss.dll version3 is less than 2000.80.765.0" test_ref="oval:org.mitre.oval:tst:2777"/>
        <criterion comment="the version of sqlservr.exe is less than 2000.80.818.0" test_ref="oval:org.mitre.oval:tst:2776"/>
        <criterion comment="the version of ssmslpcn.dll is less than 2000.80.818.0" test_ref="oval:org.mitre.oval:tst:2775"/>
        <criterion comment="the version of ssnetlib.dll is less than 2000.80.818.0" test_ref="oval:org.mitre.oval:tst:2774"/>
        <criterion comment="the version of ssnmpn70.dll is less than 2000.80.818.0" test_ref="oval:org.mitre.oval:tst:2773"/>
        <criterion comment="the version of ums.dll is less than 2000.80.816.0" test_ref="oval:org.mitre.oval:tst:2772"/>
        <criterion comment="the version of odsole70.dll is less than 2000.80.800.0" test_ref="oval:org.mitre.oval:tst:2771"/>
        <criterion comment="the version of xpweb70.dll is less than 2000.80.778.0" test_ref="oval:org.mitre.oval:tst:2770"/>
        <criterion comment="the version of msgprox.dll is less than 2000.80.765.0" test_ref="oval:org.mitre.oval:tst:2712"/>
        <criterion comment="the version of replprov.dll is less than 2000.80.798.0" test_ref="oval:org.mitre.oval:tst:2768"/>
        <criterion comment="the version of replrec.dll is less than 2000.80.765.0" test_ref="oval:org.mitre.oval:tst:2711"/>
        <criterion comment="the version of sqlvdi.dll is less than 2000.80.765.0" test_ref="oval:org.mitre.oval:tst:2710"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:298" version="6" class="vulnerability">
      <metadata>
        <title>Windows 2000 SNMPv1 Trap Handling DoS and Privilege Escalation (Test 2)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Simple Network Management Protocol (SNMP)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0013" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0013"/>
        <description>Vulnerabilities in the SNMPv1 request handling of a large number of SNMP implementations allow remote attackers to cause a denial of service or gain privileges via (1) GetRequest, (2) GetNextRequest, and (3) SetRequest messages, as demonstrated by the PROTOS c06-SNMPv1 test suite.  NOTE: It is highly likely that this candidate will be SPLIT into multiple candidates, one or more for each vendor.  This and other SNMP-related candidates will be updated when more accurate information is available.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <modified date="2004-09-20T10:31:00.000-04:00" comment="Changed CAN-2002-0012 to CAN-2002-0013.">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2004-09-22T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-10-06T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Multiple corrections and update to POSIX compatibility for ste:2884" date="2010-11-29T16:14:00.692-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-11-29T16:14:39.812-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:47.758-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:10.803-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:02:40.839-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3079"/>
          <criterion comment="the version of snmp.exe is less than 5.0.2195.4919" negate="false" test_ref="oval:org.mitre.oval:tst:2883"/>
          <criterion comment="Patch Q314147 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2959"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the SNMP service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2958"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:296" version="6" class="vulnerability">
      <metadata>
        <title>Windows 2000 RPCSS DCOM Buffer Overflow (Blaster, Test 2)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Remote Procedure Call (RPC)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0352" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0352"/>
        <description>Buffer overflow in a certain DCOM interface for RPC in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a malformed message, as exploited by the Blaster/MSblast/LovSAN and Nachi/Welchia worms.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-12-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Multiple corrections and update to POSIX compatibility for ste:2884" date="2010-11-29T16:14:00.692-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-11-29T16:14:39.133-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:47.459-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:07.705-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:02:40.510-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="File %windir%\system32\rpcrt4.dll version is less than 5.0.2195.6753" negate="false" test_ref="oval:org.mitre.oval:tst:2714"/>
          <criterion comment="Patch Windows2000-KB823980-x86-ENU.exe Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3000"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="DCOM is enabled on systems with SP3 or later">
            <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3079"/>
            <criterion comment="DCOM is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2913"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:294" version="5" class="vulnerability">
      <metadata>
        <title>Microsoft Data Access Components 2.6 Remote Data Services Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Data Access Components 2.6</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1142" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1142"/>
        <description>Heap-based buffer overflow in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 through 2.6, and Internet Explorer 5.01 through 6.0, allows remote attackers to execute code via a malformed HTTP request to the Data Stub.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-08-24T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-08-25T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-29T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-02-28T12:00:00.000-04:00" comment="removed the test for windows NT and added a test for Microsoft Data Access Components 2.6 since this definition is dependent on the Microsoft Data Access Components version and not the platform">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2005-03-02T08:52:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-23T08:09:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Standardized title." date="2007-03-02T19:00:00.375-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-03-02T19:01:00.393-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:15.008-04:00">ACCEPTED</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.220-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-10-25T16:54:19.542-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:01:10.176-05:00">ACCEPTED</status_change>
            <modified comment="References registry value for Common Files directory due to multilingual support" date="2008-04-14T11:07:00.270-04:00">
              <contributor organization="GFI Software">Clifford Farrugia</contributor>
            </modified>
            <status_change date="2008-04-14T12:27:04.258-04:00">INTERIM</status_change>
            <status_change date="2008-05-05T04:00:19.709-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Microsoft Data Access Components 2.6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2717"/>
        <criterion comment="the version of msadco.dll is less than 2.62.9119.1" negate="false" test_ref="oval:org.mitre.oval:tst:2716"/>
        <criterion comment="Patch Q329414 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2715"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2917" version="7" class="vulnerability">
      <metadata>
        <title>OLE Component Input Validation Vulnerability (Windows 2000)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows Media Player 9</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0044" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0044"/>
        <description>The OLE component in Windows 98, 2000, XP, and Server 2003, and Exchange Server 5.0 through 2003, does not properly validate the lengths of messages for certain OLE data, which allows remote attackers to execute arbitrary code, aka the "Input Validation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-02-15T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-02-18T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-29T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-17T12:00:00.000-04:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2005-06-22T12:35:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected and tightened regular expression in ste:2610" date="2010-12-02T11:46:00.307-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-12-02T11:47:27.917-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:47.125-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:44:01.745-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:02:39.740-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 (sp4 or earlier) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 5 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2790"/>
        </criteria>
        <criterion comment="the version of ole32.dll is less than 5.0.2195.7021" negate="false" test_ref="oval:org.mitre.oval:tst:1109"/>
        <criterion comment="the patch KB873333 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1485"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:291" version="3" class="vulnerability">
      <metadata>
        <title>Unchecked Buffer in Password Encryption Procedure</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft SQL Server 2000</product>
          <product>Microsoft SQL Server 2000 Desktop Engine (WMSDE)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0624" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0624"/>
        <description>Buffer overflow in the password encryption function of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows remote attackers to gain control of the database and execute arbitrary code via SQL Server Authentication, aka "Unchecked Buffer in Password Encryption Procedure."</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
            </submitted>
            <modified date="2005-04-08T10:31:00.000-04:00" comment="modified wft-237 - literal string corrected">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:31:00.000-04:00" comment="modified wft-65 - Corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:31:00.000-04:00" comment="modified wft-66 - corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:31:00.000-04:00" comment="modified wft-67 - Corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:31:00.000-04:00" comment="modified wft-68 - Corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:32:00.000-04:00" comment="modified wft-69 - corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:33:00.000-04:00" comment="modified wft-278 - wft-278 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-11T08:48:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:291 - SQL Server 2000 has been replaced by Microsoft SQL Server 2000" date="2014-06-02T14:57:00.519-04:00">
              <contributor organization="McAfee, Inc.">Jerome Athias</contributor>
            </modified>
            <status_change date="2014-06-02T14:58:42.803-04:00">INTERIM</status_change>
            <status_change date="2014-06-23T04:07:46.400-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Software section">
          <criterion comment="SQL Server 2000 is installed" test_ref="oval:org.mitre.oval:tst:2977"/>
          <criterion comment="the version of sqlservr.exe is less than 2000.80.650.0" test_ref="oval:org.mitre.oval:tst:2718"/>
          <criterion comment="the version of odsole70.dll is less than 2000.80.606.0" test_ref="oval:org.mitre.oval:tst:2925"/>
          <criterion comment="the version of xpqueue.dll is less than 2000.80.606.0" test_ref="oval:org.mitre.oval:tst:2924"/>
          <criterion comment="the version of xprepl.dll is less than 2000.80.606.0" test_ref="oval:org.mitre.oval:tst:2923"/>
          <criterion comment="the version of xplog70.dll is less than 2000.80.606.0" test_ref="oval:org.mitre.oval:tst:2922"/>
          <criterion comment="the version of xpweb70.dll is less than 2000.80.606.0" test_ref="oval:org.mitre.oval:tst:2921"/>
          <criterion comment="the version of xpstar.dll is less than 2000.80.628.0" test_ref="oval:org.mitre.oval:tst:2920"/>
        </criteria>
        <criteria operator="AND" comment="Configuration section">
          <criterion comment="Mixed Mode Enabled" test_ref="oval:org.mitre.oval:tst:2975"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2906" version="4" class="vulnerability">
      <metadata>
        <title>Windows 2000, IE v5.01 CSS Heap Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0842" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0842"/>
        <description>Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from "memory corruption") via certain malformed Cascading Style Sheet (CSS) elements that trigger heap-based buffer overflows, as demonstrated using the "&lt;STYLE>@;/*" string, possibly due to a missing comment terminator that may cause an invalid length to trigger a large memory copy operation, aka the "CSS Heap Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-19T04:45:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed ste:2614: set datatype to version.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:54:00.319-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:59:39.545-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:14.473-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:33.183-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:13.890-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3534.2800" negate="false" test_ref="oval:org.mitre.oval:tst:519"/>
          <criterion comment="the patch kb834707-ie501sp4 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:518"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29" version="7" class="vulnerability">
      <metadata>
        <title>Windows 2000 IIS Heap Overrun in HTR Chunked Encoding</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0364" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0364"/>
        <description>Buffer overflow in the chunked encoding transfer mechanism in IIS 4.0 and 5.0 allows attackers to execute arbitrary code via the processing of HTR request sessions, aka "Heap Overrun in HTR Chunked Encoding Could Enable Web Server Compromise."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected to use a forward slash as the separator in the key." date="2007-05-07T15:59:00.150-04:00">
              <contributor organization="Secure Elements, Inc.">Glenn Strickland</contributor>
            </modified>
            <status_change date="2007-05-07T16:04:54.297-04:00">INTERIM</status_change>
            <status_change date="2007-05-23T15:05:42.741-04:00">ACCEPTED</status_change>
            <modified comment="Multiple corrections and update to POSIX compatibility for ste:2884" date="2010-11-29T16:14:00.692-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-11-29T16:14:40.185-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:46.670-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:43.250-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:02:39.320-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
          <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
          <criterion comment="File %windir%\system32\inetsrv\ism.dll version is less than 5.0.2195.5671" negate="false" test_ref="oval:org.mitre.oval:tst:3059"/>
          <criterion comment="Patch Q321599 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3058"/>
          <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
          <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
          <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3079"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="ism.dll mapping exists" negate="false" test_ref="oval:org.mitre.oval:tst:3057"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:288" class="vulnerability" version="1">
      <metadata>
        <title>WMI Object Broker Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Visual Studio</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4704" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4704"/>
        <description>Cross-zone scripting vulnerability in the WMI Object Broker (WMIScriptUtils.WMIObjectBroker2) ActiveX control (WmiScriptUtils.dll) in Microsoft Visual Studio 2005 allows remote attackers to bypass Internet zone restrictions and execute arbitrary code by instantiating dangerous objects, aka "WMI Object Broker Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-12-13T08:17:04">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-12-14T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:53:52.674-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:14.308-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Visual Studio 2005 is installed." definition_ref="oval:org.mitre.oval:def:426"/>
        <criterion comment="The version of WmiScriptUtils.dll is less than 8.0.50727.236." test_ref="oval:org.mitre.oval:tst:150"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:285" version="2" class="vulnerability">
      <metadata>
        <title>XSLT Buffer Overrun Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft XML Core Services</product>
        </affected>
        <reference ref_id="CVE-2006-4686" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4686" source="CVE"/>
        <description>Buffer overflow in the Extensible Stylesheet Language Transformations (XSLT) processing in Microsoft XML Parser 2.6 and XML Core Services 3.0 through 6.0 allows remote attackers to execute arbitrary code via a crafted Web page.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-10-11T05:29:41">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-13T14:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-31T19:35:36.018-05:00">INTERIM</status_change>
            <status_change date="2006-11-21T21:27:44.869-05:00">ACCEPTED</status_change>
            <modified comment="Changed the location of MSXML5.dll, which is installed as a part of Office 2003 and Office 2007" date="2008-11-19T10:37:00.716-05:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2008-11-19T10:38:59.866-05:00">INTERIM</status_change>
            <status_change date="2008-12-08T04:00:47.023-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="Microsoft XML Core Services 3 is installed" definition_ref="oval:org.mitre.oval:def:415"/>
          <criterion comment="The version of Msxml3.dll is less than 8.70.1113.0." test_ref="oval:org.mitre.oval:tst:34"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft XML Core Services 4 is installed" definition_ref="oval:org.mitre.oval:def:1002"/>
          <criterion comment="The version of Msxml4.dll is less than 4.20.9839.0." test_ref="oval:org.mitre.oval:tst:72"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft XML Core Services 5 is installed" definition_ref="oval:org.mitre.oval:def:493"/>
          <criterion comment="The version of Msxml5.dll is less than 5.10.2930.0." test_ref="oval:org.mitre.oval:tst:87"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft XML Core Services 6 is installed" definition_ref="oval:org.mitre.oval:def:454"/>
          <criterion comment="The version of Msxml6.dll is less than 6.0.3888.0." test_ref="oval:org.mitre.oval:tst:32"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2847" version="2" class="vulnerability">
      <metadata>
        <title>Windows 2000 Windows POSIX Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>POSIX</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0210" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0210"/>
        <description>The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by modifying message length values and causing a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-08-04T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-09-24T23:42:00.000-04:00" comment="Fixed typo in obj:503, referenced by tst:609.  Was 'Subsystem' instead of 'SubSystems'.  Fix implemented by Matthew Wojcik of MITRE.">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <modified date="2006-09-23T20:21:00.000-04:00" comment="Replaced use of tst:3085 to test for Windows 2000 with extended inventory definition def:85.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-09-24T23:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-10T20:39:59.309-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <extend_definition comment="Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <criterion comment="the patch kb841872 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:612"/>
          <criterion comment="the version of psxss.exe is less than 5.0.2195.6929" negate="false" test_ref="oval:org.mitre.oval:tst:473"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="POSIX is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:609"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2830" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 IE HTML Help ActiveX control Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1043" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1043"/>
        <description>Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to execute arbitrary code by using the "Related Topics" command in the Help ActiveX Control (hhctrl.ocx) to open a Help popup window containing the PCHealth tools.htm file in the local zone and injecting Javascript to be executed, as demonstrated using "writehta.txt" and the ADODB recordset, which saves a .HTA file to the local system, aka the "HTML Help ActiveX control Cross Domain Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-02-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-02-11T12:00:00.000-04:00">DRAFT</status_change>
            <modified date="2005-03-01T12:00:00.000-04:00" comment="Removed software test to check for Windows service Packs">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </modified>
            <modified date="2005-03-24T12:00:00.000-04:00" comment="Added a configuration test to see if ActiveX controls are enabled.">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </modified>
            <status_change date="2005-04-13T12:15:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-05-04T12:33:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="the version of hhctrl.ocx is less than 5.2.3790.233" negate="false" test_ref="oval:org.mitre.oval:tst:971"/>
          <criterion comment="the patch kb890175 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:972"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2786" version="4" class="vulnerability">
      <metadata>
        <title>IE5.01,SP4 Content Advisor Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0555" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0555"/>
        <description>Buffer overflow in the Content Advisor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a crafted Content Advisor file, aka "Content Advisor Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-05-11T05:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed ste:2614: set datatype to version.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:54:00.319-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:59:41.384-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:13.825-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:45.123-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:13.746-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3826.2400" negate="false" test_ref="oval:org.mitre.oval:tst:567"/>
          <criterion comment="the patch kb890923 is installed (Win2K SP4  Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:566"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:277" version="2" class="vulnerability">
      <metadata>
        <title>SMB Session Digital Signature Sidestep</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>SMB Signing (Server Message Block)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1256" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1256"/>
        <description>The SMB signing capability in the Server Message Block (SMB) protocol in Microsoft Windows 2000 and Windows XP allows attackers to disable the digital signing settings in an SMB session to force the data to be sent unsigned, then inject data into the session without detection, e.g. by modifying group policy information sent from a domain controller.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-16T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-27T11:09:00.000-04:00" comment="modified wft-276 - Changed test to match comment">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="the version of srvsvc.dll is less than 5.0.2195.6110" negate="false" test_ref="oval:org.mitre.oval:tst:2730"/>
          <criterion comment="Patch Q329170 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2729"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="SMB Signing enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2728"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2753" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 Program Group Converter Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Program Group Converter</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0572" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0572"/>
        <description>Buffer overflow in the Windows Program Group Converter (grpconv.exe) may allow remote attackers to execute arbitrary code via a shell: URL with a long filename and a .grp extension, which is not properly handled when the shell capability launches grpconv.exe.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-14T03:39:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="the version of grpconv.exe (system32) is less than 5.0.2195.6966" negate="false" test_ref="oval:org.mitre.oval:tst:479"/>
        <criterion comment="the patch q841356 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:739"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2738" version="1" class="vulnerability">
      <metadata>
        <title>Microsoft Office Visio Professional URL Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Office Visio Professional 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0848" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0848"/>
        <description>Buffer overflow in Microsoft Office XP allows remote attackers to execute arbitrary code via a link with a URL file location containing long inputs after (1) "%00 (null byte) in .doc filenames or (2) "%0a" (carriage return) in .rtf filenames.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-29T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2005-03-29T08:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-13T12:15:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-05-04T12:33:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Microsoft Office Visio Professional 2002 with service pack 2" negate="false" test_ref="oval:org.mitre.oval:tst:481"/>
        <criterion comment="Patch KB873354 installed" negate="true" test_ref="oval:org.mitre.oval:tst:480"/>
        <criterion comment="the version of mso.dll is less than 10.0.6735.0" negate="false" test_ref="oval:org.mitre.oval:tst:554"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2730" version="5" class="vulnerability">
      <metadata>
        <title>Microsoft Data Access Components 2.5 Remote Data Services Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Data Access Components 2.5</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1142" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1142"/>
        <description>Heap-based buffer overflow in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 through 2.6, and Internet Explorer 5.01 through 6.0, allows remote attackers to execute code via a malformed HTTP request to the Data Stub.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-08-24T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-08-25T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-29T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-02-28T12:00:00.000-04:00" comment="removed the test for windows NT and added a test for Microsoft Data Access Components 2.5 since this definition is dependent on the Microsoft Data Access Components version and not the platform">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2005-03-02T08:52:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-23T08:09:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed title." date="2007-03-02T18:54:00.290-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-03-02T18:55:52.307-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:13.972-04:00">ACCEPTED</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.220-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-10-25T16:54:20.160-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:01:09.900-05:00">ACCEPTED</status_change>
            <modified comment="References registry value for Common Files directory due to multilingual support" date="2008-04-14T11:07:00.270-04:00">
              <contributor organization="GFI Software">Clifford Farrugia</contributor>
            </modified>
            <status_change date="2008-04-14T12:27:08.969-04:00">INTERIM</status_change>
            <status_change date="2008-05-05T04:00:18.440-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Microsoft Data Access Components 2.5 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2576"/>
        <criterion comment="the version of msadco.dll is less than 2.53.6202.0" negate="false" test_ref="oval:org.mitre.oval:tst:483"/>
        <criterion comment="Patch Q329414 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2715"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:272" version="4" class="vulnerability">
      <metadata>
        <title>IE v6.0 Domain Restriction Bypass Cross-Frame Scripting</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1217" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1217"/>
        <description>Cross-Frame scripting vulnerability in the WebBrowser control as used in Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code, read arbitrary files, or conduct other unauthorized activities via script that accesses the Document property, which bypasses &lt;frame> and &lt;iframe> domain restrictions.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-27T05:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-03-09T05:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Changed IE registry test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:44.985-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:13.673-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the version of mshtml.dll is less than 6.0.2722.900" negate="false" test_ref="oval:org.mitre.oval:tst:2884"/>
        <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
        <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
        <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:271" version="2" class="vulnerability">
      <metadata>
        <title>SQL Server OpenDataSource/OpenRowset Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft SQL Server 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0056" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0056"/>
        <description>Buffer overflow in SQL Server 7.0 and 2000 allows remote attackers to execute arbitrary code via a long OLE DB provider name to (1) OpenDataSource or (2) OpenRowset in an ad hoc connection.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
            </submitted>
            <modified date="2005-04-08T10:31:00.000-04:00" comment="modified wft-275 - wft-275 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T12:00:00.000-04:00" comment="modified wft-274 - wft-274 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-11T08:48:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:20:00.000-04:00" comment="modified wft-274 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-09-27T01:22:00.000-04:00" comment="modified wft-275 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="SQL Server 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2977"/>
        <criterion comment="File sqlservr.exe version3 is less than 2000.80.578.0" negate="false" test_ref="oval:org.mitre.oval:tst:2732"/>
        <criterion comment="File xpstar.dll version3 is less than 2000.80.561.0" negate="false" test_ref="oval:org.mitre.oval:tst:2731"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27" version="10" class="vulnerability">
      <metadata>
        <title>IE v5.01 Content Disposition/Type Arbitrary Code Execution</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0193" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0193"/>
        <description>Microsoft Internet Explorer 5.01 and 6.0 allow remote attackers to execute arbitrary code via malformed Content-Disposition and Content-Type header fields that cause the application for the spoofed file type to pass the file back to the operating system for handling rather than raise an error message, aka the first variant of the "Content Disposition" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-27T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2005-03-07T12:00:00.000-04:00" comment="modified wrt-222 - changed pattern match">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-03-09T07:55:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-29T07:59:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-07-03T12:56:00.000-04:00" comment="Added negate=true attribute to criteria sub-block to fix conversion error from OVAL 4.2 to OVAL 5.0">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-07-03T12:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:19.605-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2875 set datatype to version on version element. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-12T20:46:00.631-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-12T20:47:59.736-05:00">INTERIM</status_change>
            <modified comment="Corrected ste:2873. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-12T20:52:00.978-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <modified comment="Corrected ste:2874. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-12T21:00:00.301-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <modified comment="Corrected ste:2871. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-12T21:03:00.158-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <modified comment="Corrected ste:2872. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-12T21:06:00.183-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <modified comment="Corrected ste:2870. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:36:00.896-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <modified comment="Corrected ste:2869. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:39:00.994-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <modified comment="Corrected ste:2868. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:41:00.387-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-02-20T13:40:13.024-05:00">ACCEPTED</status_change>
            <modified comment="Multiple corrections and update to POSIX compatibility for ste:2878" date="2010-11-29T16:13:00.904-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-11-29T16:14:05.286-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:45.973-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:42.368-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:02:37.646-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:45.383-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:13.538-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Internet Explorer 5.01 Installed">
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3070"/>
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3069"/>
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3068"/>
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3067"/>
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3066"/>
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3065"/>
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3064"/>
          <criterion comment="Internet Explorer 5.01 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3063"/>
        </criteria>
        <criterion comment="the version of mshtml.dll is less than 5.0.3504.2500" negate="false" test_ref="oval:org.mitre.oval:tst:3062"/>
        <criterion comment="the patch q321232 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3119"/>
        <criterion comment="the patch q323759 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3118"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed" negate="true">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="SP4 or later Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3073"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2692" version="5" class="vulnerability">
      <metadata>
        <title>IE5.01,SP3 DHTML Method Heap Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0055" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0055"/>
        <description>Internet Explorer 5.01, 5.5, and 6 does not properly validate buffers when handling certain DHTML methods including the createControlRange Javascript function, which allows remote attackers to execute arbitrary code, aka the "DHTML Method Heap Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-03-23T08:09:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-13T12:15:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-05-04T12:33:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed test to check kb867282.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2824. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:48:00.494-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:52:26.331-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:12.698-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:39.572-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:13.428-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3015"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3528.700" negate="false" test_ref="oval:org.mitre.oval:tst:749"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2671" version="6" class="vulnerability">
      <metadata>
        <title>Windows 2000 Certificate Validation Identity Spoofing Vulnerability (Test 2)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Certificate Validation</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0862" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0862"/>
        <description>The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for Mac, do not properly verify the Basic Constraints of intermediate CA-signed X.509 certificates, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack for SSL sessions, as originally reported for Internet Explorer and IIS.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-11T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <modified date="2004-07-12T12:00:00.000-04:00" comment="negated patch info.">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2004-07-13T12:00:00.000-04:00" comment="Added superceding patch info.">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2004-07-14T12:00:00.000-04:00" comment="Changed to DRAFT">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-08-04T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-06-08T03:17:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-29T06:49:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed regex in ste:2889.  Implemented by Matthew Wojcik." date="2007-03-06T18:19:00.507-05:00">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2007-03-06T18:21:13.649-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:13.745-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:22.072-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:02:35.841-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 (sp3 or earlier) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="the version of cryptdlg.dll is less then 5.0.1558.6072" negate="false" test_ref="oval:org.mitre.oval:tst:1229"/>
        <criterion comment="the patch Q329115 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1231"/>
        <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:264" version="6" class="vulnerability">
      <metadata>
        <title>Windows 2000 RPCSS DCOM Buffer Overflow (Blaster, Test 1)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0715" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0715"/>
        <description>Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed DCERPC DCOM object activation request packet with modified length fields, a different vulnerability than CVE-2003-0352 (Blaster/Nachi) and CVE-2003-0528.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-12-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Multiple corrections and update to POSIX compatibility for ste:2884" date="2010-11-29T16:14:00.692-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-11-29T16:14:38.536-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:45.273-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:33.111-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:02:34.353-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="the version of rpcrt4.dll is less than 5.0.2195.6802" negate="false" test_ref="oval:org.mitre.oval:tst:2914"/>
          <criterion comment="the patch kb824146 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:3082"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="DCOM is enabled on systems with SP3 or later">
            <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3079"/>
            <criterion comment="DCOM is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2913"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26317" version="3" class="vulnerability">
      <metadata>
        <title>Allows remote attackers to spoof web sites via a crafted HTML document</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-1451" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1451"/>
        <description>Microsoft Internet Explorer 8 and 9, when the Proxy Settings configuration has the same Proxy address and Port values in the HTTP and Secure rows, does not ensure that the SSL lock icon is consistent with the Address bar, which makes it easier for remote attackers to spoof web sites via a crafted HTML document that triggers many HTTPS requests to an arbitrary host, followed by an HTTPS request to a trusted host and then an HTTP request to an untrusted host, a related issue to CVE-2013-1450.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-03T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </submitted>
            <status_change date="2014-09-11T08:03:45.045-04:00">DRAFT</status_change>
            <status_change date="2014-09-29T04:00:18.248-04:00">INTERIM</status_change>
            <status_change date="2014-10-20T04:00:25.447-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
        <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26308" version="3" class="vulnerability">
      <metadata>
        <title>Allows remote attackers to obtain sensitive information intended for a specific host via a crafted HTML document</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-1450" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1450"/>
        <description>Microsoft Internet Explorer 8 and 9, when the Proxy Settings configuration has the same Proxy address and Port values in the HTTP and Secure rows, does not properly reuse TCP sessions to the proxy server, which allows remote attackers to obtain sensitive information intended for a specific host via a crafted HTML document that triggers many HTTPS requests and then triggers an HTTP request to that host, as demonstrated by reading a Cookie header, aka MSRC 12096gd.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-03T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </submitted>
            <status_change date="2014-09-11T08:03:35.872-04:00">DRAFT</status_change>
            <status_change date="2014-09-29T04:00:18.073-04:00">INTERIM</status_change>
            <status_change date="2014-10-20T04:00:25.246-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
        <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26208" version="3" class="vulnerability">
      <metadata>
        <title>Denial of service (memory corruption) by leveraging access to a Low integrity process.</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2012-1545" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1545"/>
        <description>Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, allows remote attackers to bypass Protected Mode or cause a denial of service (memory corruption) by leveraging access to a Low integrity process, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2012.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-03T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </submitted>
            <status_change date="2014-09-11T08:03:41.415-04:00">DRAFT</status_change>
            <status_change date="2014-09-29T04:00:16.656-04:00">INTERIM</status_change>
            <status_change date="2014-10-20T04:00:22.408-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
        <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
        <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
        <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
        <criterion comment="Check if Internet Explorer 10 Consumer Preview is installed" test_ref="oval:org.mitre.oval:tst:122132"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11985" version="9" class="inventory">
      <metadata>
        <title>Microsoft Internet Explorer 9 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 9</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:ie:9"/>
        <description>A version of Microsoft Internet Explorer 9 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-03-15T15:15:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </submitted>
            <status_change date="2011-03-16T11:15:52.347-04:00">DRAFT</status_change>
            <status_change date="2011-04-04T04:00:07.004-04:00">INTERIM</status_change>
            <status_change date="2011-04-25T04:00:07.313-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:09.181-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:09.181-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:00:36.550-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:12091 - New Microsoft Patch Tuesday December 2012 definitions." date="2012-12-12T18:47:00.575-05:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-12-12T18:55:58.342-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:00:07.525-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:59.975-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:10.220-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Internet Explorer 9 is installed" test_ref="oval:org.mitre.oval:tst:42359"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:262" version="2" class="vulnerability">
      <metadata>
        <title>Windows 2000 Kernel Debugger-based Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0112" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0112"/>
        <description>Buffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-11-02T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-11-03T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-12-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-01-06T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-06-08T03:17:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-29T06:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="the version of kernel32.dll is less than 5.0.2195.6011" negate="false" test_ref="oval:org.mitre.oval:tst:2741"/>
        <criterion comment="the patch Q811493 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2885"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26" version="6" class="vulnerability">
      <metadata>
        <title>Windows 2000 Network Connection Manager Privilege Escalation</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Network Connection Manager (NCM)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0720" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0720"/>
        <description>A handler routine for the Network Connection Manager (NCM) in Windows 2000 allows local users to gain privileges via a complex attack that causes the handler to run in the LocalSystem context with user-specified code.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <modified date="2005-03-07T12:00:00.000-04:00" comment="modified wrt-222 - changed pattern match">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-03-09T07:55:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-29T07:59:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Multiple corrections and update to POSIX compatibility for ste:2878" date="2010-11-29T16:13:00.904-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-11-29T16:14:05.025-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:44.954-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:42.085-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:02:33.861-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="SP4 or later Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3073"/>
        <criterion comment="the version of netman.dll is less than 5.0.2195.5974" negate="false" test_ref="oval:org.mitre.oval:tst:3072"/>
        <criterion comment="Patch Q326886 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3071"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:258" version="5" class="vulnerability">
      <metadata>
        <title>IE5.01,SP3 PNG Image Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1211" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1211"/>
        <description>Buffer overflow in the PNG image rendering component of Microsoft Internet Explorer allows remote attackers to execute arbitrary code via a crafted PNG file.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-22T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-06-22T06:22:00.000-04:00">DRAFT</status_change>
            <modified date="2005-06-24T12:00:00.000-04:00" comment="added description">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-17T04:13:00.000-04:00" comment="Fixed registry_object obj:1557 by moving PNGFilter.CoPNGFilter from name to end of key, and setting xsi:nil to true on name.  Modified by Harvey Rubinovitz">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2006-10-17T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-11-14T08:57:57.024-05:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2824. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:48:00.494-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:52:27.298-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:11.781-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:40.469-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:13.273-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3015"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3541.2700" negate="false" test_ref="oval:org.mitre.oval:tst:2751"/>
          <criterion comment="the patch kb883939 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2750"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="PNG image rendering enabled in Internet Explorer" negate="false" test_ref="oval:org.mitre.oval:tst:2749"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:257" version="7" class="vulnerability">
      <metadata>
        <title>COM Object Instantiation Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 5</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0219" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0219"/>
        <description>Microsoft Internet Explorer 5.01, 6, and 7 uses certain COM objects from (1) Msb1fren.dll, (2) Htmlmm.ocx, and (3) Blnmgrps.dll as ActiveX controls, which allows remote attackers to execute arbitrary code via unspecified vectors, a different issue than CVE-2006-4697.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-02-14T09:49:32">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-02-16T21:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:17:13.595-04:00">INTERIM</status_change>
            <status_change date="2007-04-10T13:44:24.373-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:257 - The extended definition was replaced with criteria block." date="2014-01-14T17:16:00.146-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-14T17:18:00.481-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:04:44.454-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:40.373-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:13.176-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:257 - Modified vulnerabilities - a lot of fixes" date="2015-07-22T13:29:00.390-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-22T13:32:16.281-04:00">INTERIM</status_change>
            <status_change date="2015-08-10T04:00:25.832-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Server 2003-Gold (IE7)">
          <extend_definition comment="Microsoft Windows Server 2003 (x86) Gold is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="the version of mshtml.dll is less than 7.0.6000.16414" test_ref="oval:org.mitre.oval:tst:3906"/>
        </criteria>
        <criteria operator="AND" comment="XP,SP1 (64-bit) and Server 2003, SP1 (IE7)">
          <criteria operator="OR" comment="Windows XP (64-bit,SP1) or Server 2003 (SP1) is installed">
            <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="the version of mshtml.dll is less than 7.0.6000.16414" test_ref="oval:org.mitre.oval:tst:3906"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 on Windows XP,SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="the version of mshtml.dll is less than 7.0.6000.16414" test_ref="oval:org.mitre.oval:tst:3906"/>
        </criteria>
        <criteria operator="AND" comment="Server 2003-Gold (IE 6)">
          <extend_definition comment="Microsoft Windows Server 2003 (x86) Gold is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.630" test_ref="oval:org.mitre.oval:tst:3764"/>
        </criteria>
        <criteria operator="AND" comment="XP,SP1 (64-bit) and Server 2003, SP1 (IE6)">
          <criteria operator="OR" comment="Windows XP (64-bit,SP1) or Server 2003 (SP1) is installed">
            <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2858" test_ref="oval:org.mitre.oval:tst:3187"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Windows XP,SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2900.3059" test_ref="oval:org.mitre.oval:tst:4144"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1589" test_ref="oval:org.mitre.oval:tst:3560"/>
        </criteria>
        <criteria operator="AND" comment="IE 5.01,SP4 on Win2k,SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3849.500" test_ref="oval:org.mitre.oval:tst:3802"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2568" version="2" class="vulnerability">
      <metadata>
        <title>License Logging Service Vulnerability (Windows 2000)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Data Access Components 2.8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0050" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0050"/>
        <description>The License Logging service for Windows NT Server, Windows 2000 Server, and Windows Server 2003 does not properly validate the length of messages, which leads to an "unchecked buffer" and allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, aka the "License Logging Service Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-29T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2005-03-29T08:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-13T12:15:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-05-04T12:33:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-31T04:13:00.000-04:00" comment="Replaced reference to obj:1374 with reference to obj:1550 since it references Product\Options and not ProductOptions in the controlset registry key.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:53:52.285-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows 2000 Server is installed">
            <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
            <criteria operator="OR" comment="Windows NT server product option">
              <criterion comment="this is an NT Server (stand-alone)" negate="false" test_ref="oval:org.mitre.oval:tst:2408"/>
              <criterion comment="this is an NT Server (domain controller)" negate="false" test_ref="oval:org.mitre.oval:tst:3035"/>
            </criteria>
          </criteria>
          <criterion comment="the patch kb885834 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2477"/>
          <criterion comment="the version of Llssrv.exe is less than 5.0.2195.7021" negate="false" test_ref="oval:org.mitre.oval:tst:513"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="license logging service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2475"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2562" version="6" class="vulnerability">
      <metadata>
        <title>Windows 2000 Font Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0060" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0060"/>
        <description>Buffer overflow in the font processing component of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-02T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2005-05-04T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-06-17T12:00:00.000-04:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2005-07-27T10:37:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected and tightened regular expression in ste:2610" date="2010-12-02T11:46:00.307-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-12-02T11:47:28.161-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:44.627-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:15.813-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:02:32.900-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 (sp4 or earlier) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 5 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2790"/>
        </criteria>
        <criterion comment="The version of Ntoskrnl.exe is less than 5.0.2195.7035" negate="false" test_ref="oval:org.mitre.oval:tst:2358"/>
        <criterion comment="the patch KB890859 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2737"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2541" version="5" class="vulnerability">
      <metadata>
        <title>WINS Association Context Vulnerability (Windows 2000)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1080" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1080"/>
        <description>The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remote attackers to write to arbitrary memory locations and possibly execute arbitrary code via a modified memory pointer in a WINS replication packet to TCP port 42, aka the "Association Context Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-01-12T12:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T09:25:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-31T04:13:00.000-04:00" comment="Replaced reference to obj:1374 with reference to obj:1550 since it references Product\Options and not ProductOptions in the controlset registry key.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:53:52.038-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:29.262-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:02:30.956-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows 2000 Server is installed">
            <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
            <criteria operator="OR" comment="Windows NT server product option">
              <criterion comment="this is an NT Server (stand-alone)" negate="false" test_ref="oval:org.mitre.oval:tst:2408"/>
              <criterion comment="this is an NT Server (domain controller)" negate="false" test_ref="oval:org.mitre.oval:tst:3035"/>
            </criteria>
          </criteria>
          <criterion comment="Win2K/XP/2003 service pack 4 (or earlier) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1247"/>
          <criterion comment="the version of wins.exe is less than 5.0.2195.7005" negate="false" test_ref="oval:org.mitre.oval:tst:517"/>
          <criterion comment="the patch KB870763 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:865"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the wins service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2405"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2537" version="4" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP4 Plug-in Navigation Address Bar Spoofing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0843" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0843"/>
        <description>Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the "Plug-in Navigation Address Bar Spoofing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-25T05:29:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-27T01:04:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-17T10:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed ste:2614: set datatype to version.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:54:00.319-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:59:44.775-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:10.762-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:37.421-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:13.018-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3534.2800" negate="false" test_ref="oval:org.mitre.oval:tst:519"/>
          <criterion comment="the patch kb834707-ie501sp4 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:518"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:253" version="6" class="vulnerability">
      <metadata>
        <title>SQL Server Format String Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0879" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0879"/>
        <description>Format string vulnerability in the C runtime functions in SQL Server 7.0 and 2000 allows attackers to cause a denial of service.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
            </submitted>
            <modified comment="Multiple corrections and update to POSIX compatibility for ste:2884" date="2010-11-29T16:14:00.692-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-11-29T16:14:39.461-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:44.405-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:32.867-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:02:30.600-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="Patch Q305601 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2754"/>
        <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3079"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25" version="7" class="vulnerability" deprecated="true">
      <metadata>
        <title>DEPRECATED: Windows 2000 IIS Chunked Encoding Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0079" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0079"/>
        <description>Buffer overflow in the chunked encoding transfer mechanism in Internet Information Server (IIS) 4.0 and 5.0 Active Server Pages allows attackers to cause a denial of service or execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected to use a forward slash as the separator in the key." date="2007-05-07T15:59:00.430-04:00">
              <contributor organization="Secure Elements, Inc.">Glenn Strickland</contributor>
            </modified>
            <status_change date="2007-05-07T16:06:11.429-04:00">INTERIM</status_change>
            <status_change date="2007-05-23T15:05:41.481-04:00">ACCEPTED</status_change>
            <modified comment="Multiple corrections and update to POSIX compatibility for ste:2884" date="2010-11-29T16:14:00.692-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-11-29T16:14:40.343-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:43.992-05:00">ACCEPTED</status_change>
            <modified comment="Use def:12501 instead" date="2011-01-20T10:03:10.960-05:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-01-20T10:03:10.960-05:00">DEPRECATED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
          <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
          <criterion comment="the version of w3svc.dll is less than 5.0.2195.5269" negate="false" test_ref="oval:org.mitre.oval:tst:3080"/>
          <criterion comment="Patch Q319733 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3095"/>
          <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
          <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
          <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3079"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="asp.dll mapping exists" negate="false" test_ref="oval:org.mitre.oval:tst:3092"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2495" version="2" class="vulnerability">
      <metadata>
        <title>Windows Utility Manager Shatter Message Vulnerability II</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Utility Manager</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0213" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0213"/>
        <description>Utility Manager in Windows 2000 launches winhlp32.exe while Utility Manager is running with raised privileges, which allows local users to gain system privileges via a "Shatter" style attack that sends a Windows message to cause Utility Manager to launch winhlp32 by directly accessing the context sensitive help and bypassing the GUI, then sending another message to winhlp32 in order to open a user-selected file, a different vulnerability than CVE-2003-0908.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2004-08-04T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added missing value to value element of ste:483. Set value to 1. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-11T21:18:00.841-05:00">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2007-01-11T21:21:35.996-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:10.539-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="the version of Sp3res.dll is less than 5.0.2195.6928" negate="false" test_ref="oval:org.mitre.oval:tst:533"/>
        <criterion comment="the version of Umandlg.dll is less than 1.0.0.5" negate="false" test_ref="oval:org.mitre.oval:tst:532"/>
        <criterion comment="the patch kb842526 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:531"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2447" version="8" class="vulnerability">
      <metadata>
        <title>Windows XP Indexing Service Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Indexing Service</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0897" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0897"/>
        <description>The Indexing Service for Microsoft Windows XP and Server 2003 does not properly validate the length of a message, which allows remote attackers to execute arbitrary code via a buffer overflow attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-23T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-03-23T08:20:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-13T12:15:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-05-04T12:33:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added tests" date="2008-11-24T14:59:00.480-05:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2008-11-24T15:05:05.501-05:00">INTERIM</status_change>
            <status_change date="2008-12-15T04:00:15.098-05:00">ACCEPTED</status_change>
            <modified comment="Multiple corrections and update to POSIX compatibility for ste:2656" date="2010-11-29T16:12:00.873-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-11-29T16:12:58.963-05:00">INTERIM</status_change>
            <modified comment="Multiple corrections and update to POSIX compatibility for ste:2878" date="2010-11-29T16:13:00.904-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-12-20T04:00:43.532-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:44:34.699-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:02:30.010-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Software section - XP">
          <criteria operator="AND" comment="Windows XP (sp1 or earlier) is installed">
            <criterion comment="Windows XP is installed" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion negate="true" comment="Win2K/XP/2003 service pack 2 (or later) is installed" test_ref="oval:org.mitre.oval:tst:2837"/>
          </criteria>
          <criterion comment="Indexing Service ciodm.dll is less than 5.1.2600.1596" test_ref="oval:org.mitre.oval:tst:537"/>
          <criterion negate="true" comment="the patch Windows XP KB871250 is installed" test_ref="oval:org.mitre.oval:tst:536"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <criteria operator="OR">
            <criterion comment="Win2K/XP/2003 service pack 3 is installed" test_ref="oval:org.mitre.oval:tst:7814"/>
            <criterion comment="SP4 or later Installed" test_ref="oval:org.mitre.oval:tst:3073"/>
          </criteria>
          <criterion comment="Indexing Service ciodm.dll is less than 5.0.2195.6981" test_ref="oval:org.mitre.oval:tst:9515"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
          <criterion comment="Indexing Service ciodm.dll is less than 5.2.3790.220" test_ref="oval:org.mitre.oval:tst:9555"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:241" version="3" class="vulnerability">
      <metadata>
        <title>Scob and Toofer Internet Explorer v5.5,SP2 Vulnerabilities</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0549" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0549"/>
        <description>The WebBrowser ActiveX control, or the Internet Explorer HTML rendering engine (MSHTML), as used in Internet Explorer 6, allows remote attackers to execute arbitrary code in the Local Security context by using the showModalDialog method and modifying the location to execute code such as Javascript, as demonstrated using (1) delayed HTTP redirect operations, and an HTTP response with a Location: header containing a "URL:" prepended to a "ms-its" protocol URI, or (2) modifying the location attribute of the window, as exploited by the Download.ject (aka Scob aka Toofer) using the ADODB.Stream object.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-08-02T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:39.400-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:12.690-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
          <criterion comment="the version of mshtml.dll is less than 5.50.4943.400" negate="false" test_ref="oval:org.mitre.oval:tst:2762"/>
          <criterion comment="the patch kb832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2802"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2385" version="5" class="vulnerability">
      <metadata>
        <title>IE5.01,SP3 Channel Definition Format Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0056" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0056"/>
        <description>Internet Explorer 5.01, 5.5, and 6 does not properly validate certain URLs in Channel Definition Format (CDF) files, which allows remote attackers to obtain sensitive information or execute arbitrary code, aka the "Channel Definition Format (CDF) Cross Domain Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-03-23T08:09:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-13T12:15:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-05-04T12:33:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed test to check kb867282.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2824. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:48:00.494-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:52:24.518-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:09.684-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:35.103-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:12.589-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3015"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3528.700" negate="false" test_ref="oval:org.mitre.oval:tst:749"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2379" version="4" class="vulnerability">
      <metadata>
        <title>Windows 2000 Media Player PNG Processing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows Media Player 9</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1244" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1244"/>
        <description>Windows Media Player 9 allows remote attackers to execute arbitrary code via a PNG file containing large (1) width or (2) height values, aka the "PNG Processing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-02-22T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-02-23T08:48:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-03-23T08:09:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-04-13T12:15:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified objects 733, 734, 735, 736, 738, and 739 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-28T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:17.953-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:895. Set datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-12T20:40:00.220-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-12T20:42:16.038-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:09.368-05:00">ACCEPTED</status_change>
            <modified comment="Removed the leading &quot;\&quot; from the key." date="2008-02-04T10:03:00.486-05:00">
              <contributor organization="Hewlett-Packard">Jeff Cheng</contributor>
            </modified>
            <status_change date="2008-02-04T10:08:43.021-05:00">INTERIM</status_change>
            <modified comment="Removed the leading &quot;\&quot; from the key." date="2008-02-04T10:03:00.093-05:00">
              <contributor organization="Hewlett-Packard">Jeff Cheng</contributor>
            </modified>
            <modified comment="Removed the leading &quot;\&quot; from the key." date="2008-02-04T10:03:00.139-05:00">
              <contributor organization="Hewlett-Packard">Jeff Cheng</contributor>
            </modified>
            <modified comment="Removed the leading &quot;\&quot; from the key." date="2008-02-04T10:03:00.121-05:00">
              <contributor organization="Hewlett-Packard">Jeff Cheng</contributor>
            </modified>
            <modified comment="Removed the leading &quot;\&quot; from the key." date="2008-02-04T10:03:00.237-05:00">
              <contributor organization="Hewlett-Packard">Jeff Cheng</contributor>
            </modified>
            <modified comment="Removed the leading &quot;\&quot; from the key." date="2008-02-04T10:03:00.221-05:00">
              <contributor organization="Hewlett-Packard">Jeff Cheng</contributor>
            </modified>
            <modified comment="Removed the leading &quot;\&quot; from the key." date="2008-02-04T10:03:00.557-05:00">
              <contributor organization="Hewlett-Packard">Jeff Cheng</contributor>
            </modified>
            <status_change date="2008-02-25T04:00:08.047-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Software section">
          <criterion comment="Windows Media Player 9.0 installed" test_ref="oval:org.mitre.oval:tst:1004"/>
          <criterion comment="the version of wmp.dll is les than 9.0.0.3250" test_ref="oval:org.mitre.oval:tst:1003"/>
          <criterion negate="true" comment="The patch KB885492 is installed on Windows 2000" test_ref="oval:org.mitre.oval:tst:552"/>
        </criteria>
        <criteria operator="AND" comment="Configuration section">
          <criteria operator="AND" comment="The files .asx, .wax, .wvx, .wpl, .wmx, .wms, .wmz EXIST">
            <criterion comment=".asx EXISTS" test_ref="oval:org.mitre.oval:tst:1001"/>
            <criterion comment=".wax EXISTS" test_ref="oval:org.mitre.oval:tst:1000"/>
            <criterion comment=".wvx EXISTS" test_ref="oval:org.mitre.oval:tst:999"/>
            <criterion comment=".wpl EXISTS" test_ref="oval:org.mitre.oval:tst:998"/>
            <criterion comment=".wmx EXISTS" test_ref="oval:org.mitre.oval:tst:997"/>
            <criterion comment=".wms EXISTS" test_ref="oval:org.mitre.oval:tst:996"/>
            <criterion comment=".wmz EXISTS" test_ref="oval:org.mitre.oval:tst:995"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:237" version="1" class="vulnerability">
      <metadata>
        <title>Troubleshooter ActiveX Control Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0662" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0662"/>
        <description>Buffer overflow in Troubleshooter ActiveX Control (Tshoot.ocx) in Microsoft Windows 2000 SP4 and earlier allows remote attackers to execute arbitrary code via an HTML document with a long argument to the RunQuery2 method.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="the version of tshoot.ocx is less than 1.0.1.2125" negate="false" test_ref="oval:org.mitre.oval:tst:2764"/>
          <criterion comment="the patch kb826232 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2763"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:236" version="5" class="vulnerability">
      <metadata>
        <title>IE v6.0,SP1 Malformed GIF Image Double-free Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1048" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1048"/>
        <description>Double free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-08-02T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T11:01:00.000-04:00" comment="modified wft-267 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:46:05.069-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:09.072-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:47.061-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:12.485-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Software section">
        <criterion comment="Internet Explorer 6 Service Pack 1 is installed" test_ref="oval:org.mitre.oval:tst:2919"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2800.1458" test_ref="oval:org.mitre.oval:tst:2765"/>
        <criterion negate="true" comment="the patch kb832894 is installed (Installed Components key)" test_ref="oval:org.mitre.oval:tst:2802"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:235" version="6" class="vulnerability">
      <metadata>
        <title>SQL Server Named Pipe Hijacking</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft SQL Server 2000</product>
          <product>Microsoft SQL Server 2000 Desktop Engine (WMSDE)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0230" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0230"/>
        <description>Microsoft SQL Server 7, 2000, and MSDE allows local users to gain privileges by hijacking a named pipe during the authentication of another user, aka the "Named Pipe Hijacking" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
            </submitted>
            <modified date="2005-01-14T12:00:00.000-04:00" comment="modified wft-62 - Added &quot;80&quot; to the registry component. So that new component value is HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft SQL Server\80\SharedCode. This key specifes the location of the  file that should be tested.">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2005-01-20T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T10:31:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-04-08T10:31:00.000-04:00" comment="modified wft-70 - Corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:32:00.000-04:00" comment="modified wft-73 - Corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:33:00.000-04:00" comment="modified wft-78 - wft-78 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:34:00.000-04:00" comment="modified wft-79 - wft-79 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:35:00.000-04:00" comment="modified wft-51 - wft-51 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:36:00.000-04:00" comment="modified wft-52 - wft-52 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:37:00.000-04:00" comment="modified wft-53 - wft-53 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:38:00.000-04:00" comment="modified wft-54 - wft-54 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:39:00.000-04:00" comment="modified wft-60 - wft-60 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:45:00.000-04:00" comment="modified wft-61 - wft-61 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:56:00.000-04:00" comment="modified wft-63 - wft-63 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T11:52:00.000-04:00" comment="modified wft-64 - wft-64 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T12:00:00.000-04:00" comment="modified wft-72 - corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-11T08:48:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:46:00.000-04:00" comment="modified wft-61 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-09-27T01:21:00.000-04:00" comment="modified wft-63 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-09-27T01:23:00.000-04:00" comment="modified wft-64 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-09-27T01:26:00.000-04:00" comment="modified wft-73 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-09-27T01:27:00.000-04:00" comment="modified wft-72 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-09-27T01:28:00.000-04:00" comment="modified wft-70 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-09-27T01:29:00.000-04:00" comment="modified wft-71 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed obj:1589, missing first character in filename due to conversion error.  Was eplprov.dll, now replprov.dll." date="2007-01-22T19:20:00.817-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-01-22T19:21:04.921-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:08.473-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:235 - SQL Server 2000 has been replaced by Microsoft SQL Server 2000" date="2014-06-02T14:58:00.754-04:00">
              <contributor organization="McAfee, Inc.">Jerome Athias</contributor>
            </modified>
            <status_change date="2014-06-02T14:59:46.268-04:00">INTERIM</status_change>
            <status_change date="2014-06-23T04:07:37.998-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="SQL Server 2000 is installed" test_ref="oval:org.mitre.oval:tst:2977"/>
        <criterion comment="File console.exe version3 is less than 2000.80.818.0" test_ref="oval:org.mitre.oval:tst:2780"/>
        <criterion comment="File dbmslpcn.dll version3 is less than 2000.80.818.0" test_ref="oval:org.mitre.oval:tst:2779"/>
        <criterion comment="File sqlmap70.dll version3 is less than 2000.80.811.0" test_ref="oval:org.mitre.oval:tst:2778"/>
        <criterion comment="File sqlrepss.dll version3 is less than 2000.80.765.0" test_ref="oval:org.mitre.oval:tst:2777"/>
        <criterion comment="the version of sqlservr.exe is less than 2000.80.818.0" test_ref="oval:org.mitre.oval:tst:2776"/>
        <criterion comment="the version of ssmslpcn.dll is less than 2000.80.818.0" test_ref="oval:org.mitre.oval:tst:2775"/>
        <criterion comment="the version of ssnetlib.dll is less than 2000.80.818.0" test_ref="oval:org.mitre.oval:tst:2774"/>
        <criterion comment="the version of ssnmpn70.dll is less than 2000.80.818.0" test_ref="oval:org.mitre.oval:tst:2773"/>
        <criterion comment="the version of ums.dll is less than 2000.80.816.0" test_ref="oval:org.mitre.oval:tst:2772"/>
        <criterion comment="the version of odsole70.dll is less than 2000.80.800.0" test_ref="oval:org.mitre.oval:tst:2771"/>
        <criterion comment="the version of xpweb70.dll is less than 2000.80.778.0" test_ref="oval:org.mitre.oval:tst:2770"/>
        <criterion comment="File msgprox.dll version3 is less than 2000.80.765.0" test_ref="oval:org.mitre.oval:tst:2769"/>
        <criterion comment="the version of replprov.dll is less than 2000.80.798.0" test_ref="oval:org.mitre.oval:tst:2768"/>
        <criterion comment="File replrec.dll version3 is less than 2000.80.765.0" test_ref="oval:org.mitre.oval:tst:2767"/>
        <criterion comment="File sqlvdi.dll version3 is less than 2000.80.765.0" test_ref="oval:org.mitre.oval:tst:2766"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2348" version="3" class="vulnerability">
      <metadata>
        <title>Windows Project Professional URL Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Project Professional 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0848" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0848"/>
        <description>Buffer overflow in Microsoft Office XP allows remote attackers to execute arbitrary code via a link with a URL file location containing long inputs after (1) "%00 (null byte) in .doc filenames or (2) "%0a" (carriage return) in .rtf filenames.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-29T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2005-03-29T08:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-13T12:15:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-05-04T12:33:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-07-11T12:00:00.000-04:00" comment="removed extra closing curly brace from obj:466">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-09-08T12:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:17.655-04:00">ACCEPTED</status_change>
            <modified comment="Fixed ste:500: datatype was int, now version.  Implemented by Matthew Wojcik." date="2007-01-23T14:36:00.930-05:00">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2007-01-23T14:44:59.057-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:08.188-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Project Professional 2002 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:555"/>
        <criterion comment="the version of mso.dll is less than 10.0.6735.0" negate="false" test_ref="oval:org.mitre.oval:tst:554"/>
        <criterion comment="Patch KB873355 installed" negate="true" test_ref="oval:org.mitre.oval:tst:553"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2324" version="5" class="vulnerability">
      <metadata>
        <title>Address Bar Spoofing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3826" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3826"/>
        <description>Microsoft Internet Explorer 7 on Windows XP SP2 allows remote attackers to prevent users from leaving a site, spoof the address bar, and conduct phishing and other attacks via repeated document.open function calls after a user requests a new page, but before the onBeforeUnload function is called.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-10-10T04:39:42">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-10-11T10:02:53.885-04:00">DRAFT</status_change>
            <modified comment="set data type to version for file_state." date="2007-10-15T13:14:00.402-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="set data type to version for file_state." date="2007-10-15T13:14:00.079-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="set data type to version for file_state." date="2007-10-15T13:14:00.628-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="set data type to version for file_state." date="2007-10-15T13:14:00.129-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="set data type to version for file_state." date="2007-10-15T13:14:00.992-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="set data type to version for file_state." date="2007-10-15T13:14:00.991-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="Corrected CVE name. The new CVE is CVE-2007-3826 rather than CVE-2007-3893." date="2007-10-26T10:05:00.291-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-11-13T12:01:08.453-05:00">INTERIM</status_change>
            <status_change date="2007-12-03T04:00:12.418-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2324 - Correcting incorrect references to 64-bit Itanium XP." date="2012-08-23T17:47:00.168-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-08-23T17:52:34.680-04:00">INTERIM</status_change>
            <status_change date="2012-09-10T04:00:51.872-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:51.612-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:12.273-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 5.01,SP4 on Win2k,SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3856.1700" test_ref="oval:org.mitre.oval:tst:4411"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win 2k, SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1601" test_ref="oval:org.mitre.oval:tst:4476"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win XP SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2900.3199" test_ref="oval:org.mitre.oval:tst:4491"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win S03 SP1">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2993" test_ref="oval:org.mitre.oval:tst:3627"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win S03 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.4134" test_ref="oval:org.mitre.oval:tst:4293"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win XP SP1 (64-bit)">
          <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2993" test_ref="oval:org.mitre.oval:tst:3627"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win XP SP2 (64-bit)">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.4134" test_ref="oval:org.mitre.oval:tst:4293"/>
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 on Windows XP and S03">
          <criteria operator="OR" comment="Windows XP or Server 2003 is installed">
            <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
            <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="the version of mshtml.dll is less than 7.0.6000.16544" test_ref="oval:org.mitre.oval:tst:4233"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 on Vista">
          <extend_definition comment="Microsoft Windows Vista is installed" definition_ref="oval:org.mitre.oval:def:228"/>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="the version of mshtml.dll is less than 7.0.6000.16546" test_ref="oval:org.mitre.oval:tst:4371"/>
        </criteria>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:232" version="1">
      <metadata>
        <title>Buffer Overrun in DHCP Client Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>DHCP Client</product>
        </affected>
        <reference ref_id="CVE-2006-2372" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2372" source="CVE"/>
        <description>Buffer overflow in the DHCP Client service for Microsoft Windows 2000 SP4, Windows XP SP1 and SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via a crafted DHCP response.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-27T12:29:17.179-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:36.164-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Win2K,SP4" operator="AND">
          <extend_definition comment="Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of dhcpcsvc.dll is less than 5.0.2195.7085" test_ref="oval:org.mitre.oval:tst:186"/>
        </criteria>
        <criteria comment="WinXP,SP1" operator="AND">
          <extend_definition comment="Windows XP, SP1 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          <criterion comment="the version of dhcpcsvc.dll is less than 5.1.2600.1847" test_ref="oval:org.mitre.oval:tst:105"/>
        </criteria>
        <criteria comment="WinXP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of dhcpcsvc.dll is less than 5.1.2600.2912" test_ref="oval:org.mitre.oval:tst:5"/>
        </criteria>
        <criteria comment="WinXP,SP1 (64-bit)" operator="AND">
          <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="the version of dhcpcsvc.dll is less than 5.2.3790.2706" test_ref="oval:org.mitre.oval:tst:103"/>
        </criteria>
        <criteria comment="S03-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="the version of dhcpcsvc.dll is less than 5.2.3790.536" test_ref="oval:org.mitre.oval:tst:82"/>
        </criteria>
        <criteria comment="S03,SP1" operator="AND">
          <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of dhcpcsvc.dll is less than 5.2.3790.2706" test_ref="oval:org.mitre.oval:tst:103"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2310" version="6" class="vulnerability">
      <metadata>
        <title>Vulnerability in RPC Could Allow Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2228" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2228"/>
        <description>rpcrt4.dll (aka the RPC runtime library) in Microsoft Windows XP SP2, XP Professional x64 Edition, Server 2003 SP1 and SP2, Server 2003 x64 Edition and x64 Edition SP2, and Vista and Vista x64 Edition allows remote attackers to cause a denial of service (RPCSS service stop and system restart) via an RPC request that uses NTLMSSP PACKET authentication with a zero-valued verification trailer signature, which triggers an invalid dereference.  NOTE: this also affects Windows 2000 SP4, although the impact is an information leak.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-10-10T04:39:42">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-10-11T10:02:53.129-04:00">DRAFT</status_change>
            <status_change date="2007-10-26T10:00:30.658-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:01:07.905-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2310 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:04:38.627-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:27.986-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2310 - Correcting incorrect references to 64-bit Itanium XP." date="2012-08-23T17:47:00.168-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-08-23T17:52:11.528-04:00">INTERIM</status_change>
            <status_change date="2012-09-10T04:00:51.347-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win2K,SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of rpcrt4.dll is less than 5.0.2195.7090" test_ref="oval:org.mitre.oval:tst:4347"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of rpcrt4.dll is less than 5.1.2600.3173" test_ref="oval:org.mitre.oval:tst:4317"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP1 (64-bit)">
          <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="the version of rpcrt4.dll is less than 5.2.3790.2971" test_ref="oval:org.mitre.oval:tst:4177"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP2 (64-bit)">
          <criterion comment="the version of rpcrt4.dll is less than 5.2.3790.4115" test_ref="oval:org.mitre.oval:tst:4469"/>
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
        </criteria>
        <criteria operator="AND" comment="S03,SP1">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of rpcrt4.dll is less than 5.2.3790.2971" test_ref="oval:org.mitre.oval:tst:4177"/>
        </criteria>
        <criteria operator="AND" comment="S03,SP2">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <criterion comment="the version of rpcrt4.dll is less than 5.2.3790.4115" test_ref="oval:org.mitre.oval:tst:4469"/>
        </criteria>
        <criteria operator="AND" comment="Windows Vista">
          <extend_definition comment="Microsoft Windows Vista is installed" definition_ref="oval:org.mitre.oval:def:228"/>
          <criterion comment="the version of rpcrt4.dll is less than 6.0.6000.16525" test_ref="oval:org.mitre.oval:tst:4232"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:231" version="2" class="vulnerability">
      <metadata>
        <title>SQL Server Extended Stored Procedure Parameter Parsing</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft SQL Server</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2000-1081" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-1081"/>
        <description>The xp_displayparamstmt function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-27T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2005-04-08T05:25:00.000-04:00" comment="modified wft-85 - wft-85 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T05:28:00.000-04:00" comment="modified wft-86 - wft-86 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T05:35:00.000-04:00" comment="modified wft-87 - wft-87 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T05:55:00.000-04:00" comment="modified wft-88 - wft-88 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-11T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-04-12T12:00:00.000-04:00" comment="modified wft-89 - wft-89 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-27T12:07:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:48:00.000-04:00" comment="modified wft-85 - Changed comment to match match">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-09-27T01:25:00.000-04:00" comment="modified wft-86 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-09-27T01:26:00.000-04:00" comment="modified wft-87 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-09-27T01:27:00.000-04:00" comment="modified wft-88 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-09-27T01:28:00.000-04:00" comment="modified wft-89 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="SQL Server 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2977"/>
        <criterion comment="File odsole70.dll Version3 is less than 2000.80.223.0" negate="false" test_ref="oval:org.mitre.oval:tst:2784"/>
        <criterion comment="File xpqueue.dll Version3 is less than 2000.80.223.0" negate="false" test_ref="oval:org.mitre.oval:tst:2783"/>
        <criterion comment="File xprepl.dll Version3 is less than 2000.80.223.0" negate="false" test_ref="oval:org.mitre.oval:tst:2782"/>
        <criterion comment="File xpstar.dll Version3 is less than 2000.80.223.0" negate="false" test_ref="oval:org.mitre.oval:tst:2781"/>
        <criterion comment="File sqlservr.exe version3 greater than or equal to 2000.80.384.0" negate="true" test_ref="oval:org.mitre.oval:tst:2966"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23" version="3" class="vulnerability">
      <metadata>
        <title>IE v5.5 Forced Script Execution</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0026" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0026"/>
        <description>Internet Explorer 5.5 and 6.0 allows remote attackers to bypass restrictions for executing scripts via an object that processes asynchronous events after the initial security checks have been made.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:45.790-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:12.135-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Internet Explorer 5.5 Installed">
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3078"/>
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3077"/>
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3076"/>
        </criteria>
        <criterion comment="the version of mshtml.dll is less than 5.50.4725.2100" negate="false" test_ref="oval:org.mitre.oval:tst:3075"/>
        <criterion comment="the patch q316059 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3121"/>
        <criterion comment="the patch q319282 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3120"/>
        <criterion comment="the patch q321232 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3119"/>
        <criterion comment="the patch q323759 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3118"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2284" version="5" class="vulnerability">
      <metadata>
        <title>Error Handling Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3893" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3893"/>
        <description>Unspecified vulnerability in Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code via unspecified vectors involving memory corruption from an unhandled error.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-10-10T04:39:42">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-10-11T10:02:54.371-04:00">DRAFT</status_change>
            <modified comment="set data type to version for file_state." date="2007-10-15T13:14:00.402-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="set data type to version for file_state." date="2007-10-15T13:14:00.079-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="set data type to version for file_state." date="2007-10-15T13:14:00.628-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="set data type to version for file_state." date="2007-10-15T13:14:00.129-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="set data type to version for file_state." date="2007-10-15T13:14:00.992-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="set data type to version for file_state." date="2007-10-15T13:14:00.991-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-11-02T07:17:46.801-04:00">INTERIM</status_change>
            <status_change date="2007-11-19T04:01:18.306-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2284 - Correcting incorrect references to 64-bit Itanium XP." date="2012-08-23T17:47:00.168-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-08-23T17:52:52.225-04:00">INTERIM</status_change>
            <status_change date="2012-09-10T04:00:50.617-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:40.886-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:11.961-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 5.01,SP4 on Win2k,SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3856.1700" test_ref="oval:org.mitre.oval:tst:4411"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win 2k, SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1601" test_ref="oval:org.mitre.oval:tst:4476"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win XP SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2900.3199" test_ref="oval:org.mitre.oval:tst:4491"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win S03 SP1">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2993" test_ref="oval:org.mitre.oval:tst:3627"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win S03 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.4134" test_ref="oval:org.mitre.oval:tst:4293"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win XP SP1 (64-bit)">
          <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2993" test_ref="oval:org.mitre.oval:tst:3627"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win XP SP2 (64-bit)">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.4134" test_ref="oval:org.mitre.oval:tst:4293"/>
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 on Windows XP and S03">
          <criteria operator="OR" comment="Windows XP or Server 2003 is installed">
            <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
            <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="the version of mshtml.dll is less than 7.0.6000.16544" test_ref="oval:org.mitre.oval:tst:4233"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 on Vista">
          <extend_definition comment="Microsoft Windows Vista is installed" definition_ref="oval:org.mitre.oval:def:228"/>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="the version of mshtml.dll is less than 7.0.6000.16546" test_ref="oval:org.mitre.oval:tst:4371"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2253" version="4" class="vulnerability">
      <metadata>
        <title>URL Parsing Memory Corruption Vulnerability (IE5.01,SP4)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0554" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0554"/>
        <description>Buffer overflow in the URL processor of Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a URL with a long hostname, aka "URL Parsing Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-05-11T05:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed ste:2614: set datatype to version.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:54:00.319-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:59:40.528-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:07.663-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:43.115-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:11.830-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3826.2400" negate="false" test_ref="oval:org.mitre.oval:tst:567"/>
          <criterion comment="the patch kb890923 is installed (Win2K SP4  Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:566"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:225" version="3" class="vulnerability">
      <metadata>
        <title>IE v5.5 Frames Cross-site Scripting Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1187" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1187"/>
        <description>Cross-site scripting vulnerability (XSS) in Internet Explorer 5.01 through 6.0 allows remote attackers to read and execute files on the local system via web pages using the &lt;frame> or &lt;iframe> element and javascript, aka "Frames Cross Site Scripting," as demonstrated using the PrivacyPolicy.dlg resource.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-27T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:48.935-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:11.752-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Internet Explorer 5.5 Installed">
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3078"/>
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3077"/>
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3076"/>
          <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
        </criteria>
        <criterion comment="the version of mshtml.dll is less than 5.50.4922.900" negate="false" test_ref="oval:org.mitre.oval:tst:2786"/>
        <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
        <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
        <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2244" version="5" class="vulnerability">
      <metadata>
        <title>Address Bar Spoofing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3892" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3892"/>
        <description>Microsoft Internet Explorer 5.01 through 7 allows remote attackers to spoof the URL address bar and other "trust UI" components via unspecified vectors, a different issue than CVE-2007-1091 and CVE-2007-3826.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-10-10T04:39:42">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-10-11T10:02:53.977-04:00">DRAFT</status_change>
            <modified comment="set data type to version for file_state." date="2007-10-15T13:14:00.402-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="set data type to version for file_state." date="2007-10-15T13:14:00.079-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="set data type to version for file_state." date="2007-10-15T13:14:00.628-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="set data type to version for file_state." date="2007-10-15T13:14:00.129-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="set data type to version for file_state." date="2007-10-15T13:14:00.992-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="set data type to version for file_state." date="2007-10-15T13:14:00.991-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-11-02T07:17:43.868-04:00">INTERIM</status_change>
            <status_change date="2007-11-19T04:01:10.254-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2244 - Correcting incorrect references to 64-bit Itanium XP." date="2012-08-23T17:47:00.168-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-08-23T17:53:05.350-04:00">INTERIM</status_change>
            <status_change date="2012-09-10T04:00:49.876-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:48.215-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:11.628-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 5.01,SP4 on Win2k,SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3856.1700" test_ref="oval:org.mitre.oval:tst:4411"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win 2k, SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1601" test_ref="oval:org.mitre.oval:tst:4476"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win XP SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2900.3199" test_ref="oval:org.mitre.oval:tst:4491"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win S03 SP1">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2993" test_ref="oval:org.mitre.oval:tst:3627"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win S03 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.4134" test_ref="oval:org.mitre.oval:tst:4293"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win XP SP1 (64-bit)">
          <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2993" test_ref="oval:org.mitre.oval:tst:3627"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win XP SP2 (64-bit)">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.4134" test_ref="oval:org.mitre.oval:tst:4293"/>
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 on Windows XP and S03">
          <criteria operator="OR" comment="Windows XP or Server 2003 is installed">
            <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
            <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="the version of mshtml.dll is less than 7.0.6000.16544" test_ref="oval:org.mitre.oval:tst:4233"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 on Vista">
          <extend_definition comment="Microsoft Windows Vista is installed" definition_ref="oval:org.mitre.oval:def:228"/>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="the version of mshtml.dll is less than 7.0.6000.16546" test_ref="oval:org.mitre.oval:tst:4371"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2232" version="5" class="vulnerability">
      <metadata>
        <title>ActiveX Object Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3041" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3041"/>
        <description>Unspecified vulnerability in the pdwizard.ocx ActiveX object for Internet Explorer 5.01, 6 SP1, and 7 allows remote attackers to execute arbitrary code via unknown vectors related to Microsoft Visual Basic 6 objects and memory corruption, aka "ActiveX Object Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-15T09:28:35">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-08-15T15:55:12.660-04:00">DRAFT</status_change>
            <modified comment="Added version datatype to file_state version element. Altered oval:org.mitre.oval:ste:3811" date="2007-08-23T14:13:00.397-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="Added version datatype to file_state version element. Altered oval:org.mitre.oval:ste:3400" date="2007-08-23T14:13:00.076-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="Added version datatype to file_state version element. Altered oval:org.mitre.oval:ste:3654" date="2007-08-23T14:13:00.971-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="Added version datatype to file_state version element. Altered oval:org.mitre.oval:ste:3361" date="2007-08-23T14:13:00.510-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="Added version datatype to file_state version element. Altered oval:org.mitre.oval:ste:3590" date="2007-08-23T14:13:00.427-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="Added version datatype to file_state version element. Altered oval:org.mitre.oval:ste:3716" date="2007-08-23T14:13:00.118-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="Added version datatype to file_state version element. Altered oval:org.mitre.oval:ste:3653" date="2007-08-23T14:13:00.466-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-09-10T14:45:27.114-04:00">INTERIM</status_change>
            <status_change date="2007-09-27T08:57:47.400-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2232 - Correcting incorrect references to 64-bit Itanium XP." date="2012-08-23T17:47:00.168-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-08-23T17:52:00.794-04:00">INTERIM</status_change>
            <status_change date="2012-09-10T04:00:49.185-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:49.265-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:04.845-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 5.01,SP4 on Win2k,SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3854.1200" test_ref="oval:org.mitre.oval:tst:4193"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win 2k, SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1597" test_ref="oval:org.mitre.oval:tst:3205"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win XP SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2900.3157" test_ref="oval:org.mitre.oval:tst:3691"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win S03 SP1">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2954" test_ref="oval:org.mitre.oval:tst:4199"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win S03 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.4106" test_ref="oval:org.mitre.oval:tst:3218"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win XP SP1 (64-bit)">
          <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2954" test_ref="oval:org.mitre.oval:tst:4199"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win XP SP2 (64-bit)">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.4106" test_ref="oval:org.mitre.oval:tst:3218"/>
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 on Windows XP and S03">
          <criteria operator="OR" comment="Windows XP  or Server 2003 is installed">
            <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
            <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="the version of mshtml.dll is less than 7.0.6000.16525" test_ref="oval:org.mitre.oval:tst:3806"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 on Vista">
          <extend_definition comment="Microsoft Windows Vista is installed" definition_ref="oval:org.mitre.oval:def:228"/>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="the version of mshtml.dll is less than 7.0.6000.16527" test_ref="oval:org.mitre.oval:tst:3501"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:221" version="2" class="vulnerability">
      <metadata>
        <title>Microsoft XML Core Services Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft XML Core Services</product>
        </affected>
        <reference ref_id="CVE-2006-4685" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4685" source="CVE"/>
        <description>The XMLHTTP ActiveX control in Microsoft XML Parser 2.6 and XML Core Services 3.0 through 6.0 does not properly handle HTTP server-side redirects, which allows remote user-assisted attackers to access content from other domains.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-10-11T05:29:41">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-13T14:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-31T19:35:32.199-05:00">INTERIM</status_change>
            <status_change date="2006-11-21T21:27:41.254-05:00">ACCEPTED</status_change>
            <modified comment="Changed the location of MSXML5.dll, which is installed as a part of Office 2003 and Office 2007" date="2008-11-19T10:37:00.716-05:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2008-11-19T10:38:59.386-05:00">INTERIM</status_change>
            <status_change date="2008-12-08T04:00:46.006-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="Microsoft XML Core Services 3 is installed" definition_ref="oval:org.mitre.oval:def:415"/>
          <criterion comment="The version of Msxml3.dll is less than 8.70.1113.0." test_ref="oval:org.mitre.oval:tst:34"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft XML Core Services 4 is installed" definition_ref="oval:org.mitre.oval:def:1002"/>
          <criterion comment="The version of Msxml4.dll is less than 4.20.9839.0." test_ref="oval:org.mitre.oval:tst:72"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft XML Core Services 5 is installed" definition_ref="oval:org.mitre.oval:def:493"/>
          <criterion comment="The version of Msxml5.dll is less than 5.10.2930.0." test_ref="oval:org.mitre.oval:tst:87"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft XML Core Services 6 is installed" definition_ref="oval:org.mitre.oval:def:454"/>
          <criterion comment="The version of Msxml6.dll is less than 6.0.3888.0." test_ref="oval:org.mitre.oval:tst:32"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:493" version="4" class="inventory">
      <metadata>
        <title>Microsoft XML Core Services 5 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft XML Core Services 5</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:xml_core_services:5"/>
        <description>Microsoft XML Core Services 5 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-10-11T05:29:41">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-13T14:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-31T19:35:45.581-05:00">INTERIM</status_change>
            <status_change date="2006-11-21T21:27:55.727-05:00">ACCEPTED</status_change>
            <modified comment="Changed the location of MSXML5.dll, which is installed as a part of Office 2003 and Office 2007" date="2008-11-19T10:37:00.716-05:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2008-11-19T10:38:59.532-05:00">INTERIM</status_change>
            <status_change date="2008-12-08T04:00:48.083-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:493 - products added to inventories" date="2015-04-17T09:39:00.289-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-04-17T09:41:23.301-04:00">INTERIM</status_change>
            <status_change date="2015-05-04T04:00:20.058-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Microsoft XML Core Services 5 is installed." test_ref="oval:org.mitre.oval:tst:49"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2207" class="vulnerability" version="1">
      <metadata>
        <title>Windows Media Player Code Execution Vulnerability Parsing Skins</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Windows Media Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3037" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3037"/>
        <description>Microsoft Windows Media Player 7.1, 9, 10, and 11 allows remote attackers to execute arbitrary code via a skin file (WMZ or WMD) with crafted header information that causes a size mismatch between compressed and decompressed data and triggers a heap-based buffer overflow, aka "Windows Media Player Code Execution Vulnerability Parsing Skins."</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-15T09:28:35">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-08-15T15:55:11.975-04:00">DRAFT</status_change>
            <modified comment="Added version datatype to file_state version element. Altered oval:org.mitre.oval:ste:3362" date="2007-08-23T14:13:00.780-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="Added version datatype to file_state version element. Altered oval:org.mitre.oval:ste:3268" date="2007-08-23T14:13:00.640-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="Added version datatype to file_state version element. Altered oval:org.mitre.oval:ste:3208" date="2007-08-23T14:13:00.697-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="Added version datatype to file_state version element. Altered oval:org.mitre.oval:ste:3715" date="2007-08-23T14:13:00.054-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="Added version datatype to file_state version element. Altered oval:org.mitre.oval:ste:3766" date="2007-08-23T14:13:00.128-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="Added version datatype to file_state version element. Altered oval:org.mitre.oval:ste:3810" date="2007-08-23T14:13:00.388-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="Added version datatype to file_state version element. Altered oval:org.mitre.oval:ste:3500" date="2007-08-23T14:13:00.056-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-09-10T14:45:26.803-04:00">INTERIM</status_change>
            <status_change date="2007-09-27T08:57:46.420-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Media Player v7.10">
          <extend_definition comment="Windows Media Player v7.1 is installed" definition_ref="oval:org.mitre.oval:def:1386"/>
          <criterion test_ref="oval:org.mitre.oval:tst:4149" comment="the version of Wmpui.dll is less than 7.10.0.3080"/>
        </criteria>
        <criteria comment="Media Player v9">
          <extend_definition comment="Windows Media Player v9 is installed" definition_ref="oval:org.mitre.oval:def:2147"/>
          <criterion test_ref="oval:org.mitre.oval:tst:3271" comment="the version of Wmp.dll is less than 9.0.0.3354"/>
        </criteria>
        <criteria comment="Media Player v10 on XP">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Windows Media Player v10 is installed" definition_ref="oval:org.mitre.oval:def:2172"/>
          <criterion test_ref="oval:org.mitre.oval:tst:4138" comment="the version of Wmp.dll is less than 10.0.0.4058"/>
        </criteria>
        <criteria comment="Media Player v11 on XP">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Windows Media Player v11 is installed" definition_ref="oval:org.mitre.oval:def:2126"/>
          <criterion test_ref="oval:org.mitre.oval:tst:4010" comment="the version of Wmp.dll is less than 11.0.5721.5230"/>
        </criteria>
        <criteria comment="Media Player v10 on S03,SP1">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2003 (x86) SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) SP1 is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP1 is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
          </criteria>
          <extend_definition comment="Windows Media Player v10 is installed" definition_ref="oval:org.mitre.oval:def:2172"/>
          <criterion test_ref="oval:org.mitre.oval:tst:3305" comment="the version of Wmp.dll is less than 10.0.0.3709"/>
        </criteria>
        <criteria comment="Media Player v10 on S03,SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2003 (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <extend_definition comment="Windows Media Player v10 is installed" definition_ref="oval:org.mitre.oval:def:2172"/>
          <criterion test_ref="oval:org.mitre.oval:tst:3348" comment="the version of Wmp.dll is less than 10.0.0.3998"/>
        </criteria>
        <criteria comment="Media Player v11 on Vista">
          <extend_definition comment="Microsoft Windows Vista is installed" definition_ref="oval:org.mitre.oval:def:228"/>
          <extend_definition comment="Windows Media Player v11 is installed" definition_ref="oval:org.mitre.oval:def:2126"/>
          <criterion test_ref="oval:org.mitre.oval:tst:3397" comment="the version of Wmp.dll is less than 11.0.6000.6336"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22" version="7" class="vulnerability" deprecated="true">
      <metadata>
        <title>DEPRECATED: Windows 2000 Variant of Chunked Encoding Buffer Overrun</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0147" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0147"/>
        <description>Buffer overflow in the ASP data transfer mechanism in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to cause a denial of service or execute code, aka "Microsoft-discovered variant of Chunked Encoding buffer overrun."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected to use a forward slash as the separator in the key." date="2007-05-07T15:59:00.430-04:00">
              <contributor organization="Secure Elements, Inc.">Glenn Strickland</contributor>
            </modified>
            <status_change date="2007-05-07T16:06:12.258-04:00">INTERIM</status_change>
            <status_change date="2007-05-23T15:05:39.243-04:00">ACCEPTED</status_change>
            <modified comment="Multiple corrections and update to POSIX compatibility for ste:2884" date="2010-11-29T16:14:00.692-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-11-29T16:14:40.276-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:42.264-05:00">ACCEPTED</status_change>
            <modified comment="Use def:12307 instead" date="2011-01-20T10:05:17.755-05:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-01-20T10:05:17.755-05:00">DEPRECATED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
          <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
          <criterion comment="the version of w3svc.dll is less than 5.0.2195.5269" negate="false" test_ref="oval:org.mitre.oval:tst:3080"/>
          <criterion comment="Patch Q319733 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3095"/>
          <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
          <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
          <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3079"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="asp.dll mapping exists" negate="false" test_ref="oval:org.mitre.oval:tst:3092"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2188" version="5" class="vulnerability">
      <metadata>
        <title>Win2k Path MTU Discovery Attack Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1060" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1060"/>
        <description>Multiple TCP/IP and ICMP implementations, when using Path MTU (PMTU) discovery (PMTUD), allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via forged ICMP ("Fragmentation Needed and Don't Fragment was Set") packets with a low next-hop MTU value, aka the "Path MTU discovery attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-04-22T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-04-27T12:06:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-11-06T04:13:00.000-04:00" comment="Replaced reference to var:200 with reference to var:201 in obj:588 since tcpip.sys is located in \system32\drivers and not \system32.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:53:51.442-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:09.289-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:02:25.416-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or earlier) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1247"/>
          <criterion comment="the version of Tcpip.sys is less than 5.0.2195.7035" negate="false" test_ref="oval:org.mitre.oval:tst:1012"/>
          <criterion comment="the patch KB893066 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2353"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Enable Path MTU Discovery is Disabled" negate="true" test_ref="oval:org.mitre.oval:tst:2352"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:217" version="9" class="vulnerability">
      <metadata>
        <title>Help and Support Center PCHealth System Buffer Overflow (Windows 2000)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Help and Support Center (HSC)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0711" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0711"/>
        <description>Stack-based buffer overflow in the PCHealth system in the Help and Support Center function in Windows XP and Windows Server 2003 allows remote attackers to execute arbitrary code via a long query in an HCP URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-16T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-01-18T12:00:00.000-04:00" comment="Windows 2000 replaced by check for Windows 2000 SP4 or earlier">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-01-20T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-17T12:00:00.000-04:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2005-06-22T12:35:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1001 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-28T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:15.602-04:00">ACCEPTED</status_change>
            <modified comment="Corrected and tightened regular expression in ste:2610" date="2010-12-02T11:46:00.307-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-12-02T11:47:26.679-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:41.317-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:44:40.981-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:02:23.777-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Software section">
          <criterion comment="the version of itircl.dll is less than 5.2.3790.80" test_ref="oval:org.mitre.oval:tst:2792"/>
          <criterion negate="true" comment="Patch KB825119 Installed" test_ref="oval:org.mitre.oval:tst:2791"/>
          <criteria operator="AND" comment="Windows 2000 (sp4 or earlier) is installed">
            <criterion comment="Windows 2000 is installed" test_ref="oval:org.mitre.oval:tst:3085"/>
            <criterion negate="true" comment="Win2K/XP/2003 service pack 5 (or later) is installed" test_ref="oval:org.mitre.oval:tst:2790"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Configuration section">
          <criterion negate="true" comment="the HCP Protocol is registered" test_ref="oval:org.mitre.oval:tst:1477"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2162" version="5" class="vulnerability">
      <metadata>
        <title>Address Bar Spoofing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1091" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1091"/>
        <description>Microsoft Internet Explorer 7 allows remote attackers to prevent users from leaving a site, spoof the address bar, and conduct phishing and other attacks via onUnload Javascript handlers.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-10-10T04:39:42">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-10-11T10:02:54.128-04:00">DRAFT</status_change>
            <modified comment="set data type to version for file_state." date="2007-10-15T13:14:00.402-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="set data type to version for file_state." date="2007-10-15T13:14:00.079-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="set data type to version for file_state." date="2007-10-15T13:14:00.628-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="set data type to version for file_state." date="2007-10-15T13:14:00.129-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="set data type to version for file_state." date="2007-10-15T13:14:00.992-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="set data type to version for file_state." date="2007-10-15T13:14:00.991-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-11-02T07:17:40.205-04:00">INTERIM</status_change>
            <status_change date="2007-11-19T04:01:01.523-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2162 - Correcting incorrect references to 64-bit Itanium XP." date="2012-08-23T17:47:00.168-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-08-23T17:52:47.607-04:00">INTERIM</status_change>
            <status_change date="2012-09-10T04:00:48.421-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:44.588-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:48.036-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 5.01,SP4 on Win2k,SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3856.1700" test_ref="oval:org.mitre.oval:tst:4411"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win 2k, SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1601" test_ref="oval:org.mitre.oval:tst:4476"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win XP SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2900.3199" test_ref="oval:org.mitre.oval:tst:4491"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win S03 SP1">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2993" test_ref="oval:org.mitre.oval:tst:3627"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win S03 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.4134" test_ref="oval:org.mitre.oval:tst:4293"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win XP SP1 (64-bit)">
          <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2993" test_ref="oval:org.mitre.oval:tst:3627"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win XP SP2 (64-bit)">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.4134" test_ref="oval:org.mitre.oval:tst:4293"/>
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 on Windows XP and S03">
          <criteria operator="OR" comment="Windows XP or Server 2003 is installed">
            <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
            <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="the version of mshtml.dll is less than 7.0.6000.16544" test_ref="oval:org.mitre.oval:tst:4233"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 on Vista">
          <extend_definition comment="Microsoft Windows Vista is installed" definition_ref="oval:org.mitre.oval:def:228"/>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="the version of mshtml.dll is less than 7.0.6000.16546" test_ref="oval:org.mitre.oval:tst:4371"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:216" version="5" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP4 Bitmap Integer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0566" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0566"/>
        <description>Integer overflow in imgbmp.cxx for Windows 2000 allows remote attackers to execute arbitrary code via a BMP image with a large bfOffBits value.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-08-02T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:21:00.000-04:00" comment="modified wft-279 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed ste:2614: set datatype to version.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:54:00.319-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:59:39.366-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:06.770-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:52.213-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:46.464-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3819.300" negate="false" test_ref="oval:org.mitre.oval:tst:2793"/>
        <criterion comment="the patch kb832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2802"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:214" version="4" class="vulnerability">
      <metadata>
        <title>Vulnerability in Microsoft Data Access Components Could Allow Remote Code Execution</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5559" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5559"/>
        <description>The Execute method in the ADODB.Connection 2.7 and 2.8 ActiveX control objects (ADODB.Connection.2.7 and ADODB.Connection.2.8) in the Microsoft Data Access Components (MDAC) 2.5 SP3, 2.7 SP1, 2.8, and 2.8 SP1 does not properly track freed memory when the second argument is a BSTR, which allows remote attackers to cause a denial of service (Internet Explorer crash) and possibly execute arbitrary code via certain strings in the second and third arguments.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-02-13T14:38:21">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-02-20T13:20:00.000-04:00">DRAFT</status_change>
            <modified comment="Corrected XP and S03 tests to look for versions of Msado15.dll instead of Msadco.dll." date="2007-03-02T12:18:00.315-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-03-21T16:17:11.974-04:00">INTERIM</status_change>
            <status_change date="2007-04-10T13:44:23.320-04:00">ACCEPTED</status_change>
            <modified comment="References registry value for Common Files directory due to multilingual support" date="2008-04-14T11:07:00.042-04:00">
              <contributor organization="GFI Software">Clifford Farrugia</contributor>
            </modified>
            <status_change date="2008-04-14T12:24:53.469-04:00">INTERIM</status_change>
            <modified comment="References registry value for Common Files directory due to multilingual support" date="2008-04-14T11:07:00.270-04:00">
              <contributor organization="GFI Software">Clifford Farrugia</contributor>
            </modified>
            <status_change date="2008-05-05T04:00:17.294-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:214 - Modified the test for MDAC 2.8 SP1" date="2011-02-28T09:34:00.995-05:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-02-28T09:35:53.876-05:00">INTERIM</status_change>
            <status_change date="2011-03-21T04:00:14.317-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows 2000 SP4 with Microsoft Data Access Components 2.5 SP3">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Microsoft Data Access Components 2.5 (SP3) is installed" test_ref="oval:org.mitre.oval:tst:729"/>
          <criterion comment="the version of msadco.dll is less than 2.53.6307.0" test_ref="oval:org.mitre.oval:tst:4137"/>
        </criteria>
        <criteria operator="AND" comment="Windows 2000 SP4 with Microsoft Data Access Components 2.7 SP1">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Microsoft Data Access Components 2.7 (SP1) is installed" test_ref="oval:org.mitre.oval:tst:2382"/>
          <criterion comment="the version of msadco.dll is less than 2.71.9054.0" test_ref="oval:org.mitre.oval:tst:4020"/>
        </criteria>
        <criteria operator="AND" comment="Windows 2000 SP4 with Microsoft Data Access Components 2.8">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Microsoft Data Access Components 2.8 (RTM) is installed" test_ref="oval:org.mitre.oval:tst:2363"/>
          <criterion comment="the version of msadco.dll is less than 2.80.1064.0" test_ref="oval:org.mitre.oval:tst:3591"/>
        </criteria>
        <criteria operator="AND" comment="Windows 2000 SP4 with Microsoft Data Access Components 2.8 SP1">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Microsoft Data Access Components 2.8 (SP1) is installed" test_ref="oval:org.mitre.oval:tst:725"/>
          <criterion comment="the version of msadco.dll is less than 2.81.1128.0" test_ref="oval:org.mitre.oval:tst:3619"/>
        </criteria>
        <criteria operator="AND" comment="Windows XP SP2 with Microsoft Data Access Components 2.8 SP1">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="Microsoft Data Access Components 2.8 (SP1) is installed" test_ref="oval:org.mitre.oval:tst:725"/>
          <criterion comment="the version of msado15.dll is less than 2.81.1128.0" test_ref="oval:org.mitre.oval:tst:3821"/>
        </criteria>
        <criteria operator="AND" comment="Windows Server 2003 with Microsoft Data Access Components 2.8">
          <extend_definition comment="Microsoft Windows Server 2003 (x86) Gold is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="Microsoft Data Access Components 2.8 (RTM) is installed" test_ref="oval:org.mitre.oval:tst:2363"/>
          <criterion comment="the version of msado15.dll is less than 2.80.1064.0" test_ref="oval:org.mitre.oval:tst:3787"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2137" version="3" class="vulnerability">
      <metadata>
        <title>Outlook Express v5.5,SP2 Malformed Email Header Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Outlook Express</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0215" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0215"/>
        <description>Microsoft Outlook Express 5.5 and 6 allows attackers to cause a denial of service (application crash) via a malformed e-mail header.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-08-26T08:06:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2004-08-26T08:14:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-29T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed obj:533: changed Hive from HKEY_CLASSES_ROOT to HKEY_LOCAL_MACHINE.  Implemented by Harvey Rubinovitz." date="2007-01-22T01:12:00.977-05:00">
              <contributor organization="GFI Software">Daniel Tarnu</contributor>
            </modified>
            <status_change date="2007-01-22T01:12:58.320-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:06.549-05:00">ACCEPTED</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.788-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-10-25T16:52:38.332-04:00">INTERIM</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.053-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-11-13T12:01:06.364-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Outlook Express 5.5 SP2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1514"/>
          <criterion comment="the version of inetcomm.dll is less than 5.50.4942.400" negate="false" test_ref="oval:org.mitre.oval:tst:617"/>
          <criterion comment="the patch kb823353 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:668"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="all users have the preview pane disabled" negate="false" test_ref="oval:org.mitre.oval:tst:667"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:213" version="4" class="vulnerability">
      <metadata>
        <title>Windows 2000 Messenger Service Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Messenger Service</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0717" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0717"/>
        <description>The Messenger Service for Windows NT through Server 2003 does not properly verify the length of the message, which allows remote attackers to execute arbitrary code via a buffer overflow attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-16T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2004-03-29T12:00:00.000-04:00" comment="Fixed an error in the configuration section, now correctly testing that messenger service is enabled.  Before it was testing that HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Messenger\Start=2, now it is testing that it does not equal 4.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:1448 - Correction of a filename (Spwmp.dll is replaced by wkssvc.dll as per the bulletin info.) in an object oval:org.mitre.oval:obj:1448 along with comments" date="2011-09-14T12:12:00.927-04:00">
              <contributor organization="SecPod Technologies">Pradeep R B</contributor>
            </modified>
            <status_change date="2011-09-14T12:12:55.461-04:00">INTERIM</status_change>
            <status_change date="2011-10-03T04:00:04.092-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="the version of msgsvc.dll is less than 5.0.2195.6861" negate="false" test_ref="oval:org.mitre.oval:tst:2798"/>
          <criterion comment="the version of wkssvc.dll is less than 5.0.2195.6861" negate="false" test_ref="oval:org.mitre.oval:tst:2797"/>
          <criterion comment="the patch q828035 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2796"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the messenger service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2795"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:212" version="4" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP3 Malformed GIF Image Double-free Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1048" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1048"/>
        <description>Double free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-08-02T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2824. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:48:00.494-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:52:26.766-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:06.339-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:52.023-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:56.999-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Software section">
        <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" test_ref="oval:org.mitre.oval:tst:3015"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3532.300" test_ref="oval:org.mitre.oval:tst:2803"/>
        <criterion negate="true" comment="the patch kb832894 is installed (Installed Components key)" test_ref="oval:org.mitre.oval:tst:2802"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2116" class="vulnerability" version="1">
      <metadata>
        <title>Agent Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3040" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3040"/>
        <description>Stack-based buffer overflow in agentdpv.dll 2.0.0.3425 in Microsoft Agent on Windows 2000 SP4 allows remote attackers to execute arbitrary code via a crafted URL to the Agent (Agent.Control) ActiveX control, which triggers an overflow within the Agent Service (agentsrv.exe) process, a different issue than CVE-2007-1205.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-09-13T11:17:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-09-12T15:03:45.872-04:00">DRAFT</status_change>
            <status_change date="2007-10-02T08:08:11.792-04:00">INTERIM</status_change>
            <status_change date="2007-10-18T21:59:20.077-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
          <affected_cpe_list>
            <cpe>cpe:/o:microsoft:windows-nt:2000:sp4</cpe>
          </affected_cpe_list>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
        <criterion comment="the version of agentdpv.dll is less than 2.0.0.3426" test_ref="oval:org.mitre.oval:tst:3466"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2114" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 Enhanced Metafile Image Format Rendering Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Enhanced Metafile (EMF)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0209" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0209"/>
        <description>Unknown vulnerability in the Graphics Rendering Engine processes of Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats that involve "an unchecked buffer."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-13T11:11:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-10-13T01:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-10-27T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-11-17T10:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="the patch KB840987 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2356"/>
        <criterion comment="the version of gdi32.dll is less than 5.0.2195.6945" negate="false" test_ref="oval:org.mitre.oval:tst:620"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2109" version="5" class="vulnerability">
      <metadata>
        <title>ActiveX Object Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2216" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2216"/>
        <description>The tblinf32.dll (aka vstlbinf.dll) ActiveX control for Internet Explorer 5.01, 6 SP1, and 7 uses an incorrect IObjectsafety implementation, which allows remote attackers to execute arbitrary code by requesting the HelpString property, involving a crafted DLL file argument to the TypeLibInfoFromFile function, which overwrites the HelpStringDll property to call the DLLGetDocumentation function in another DLL file, aka "ActiveX Object Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-15T09:28:35">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-08-15T15:55:13.350-04:00">DRAFT</status_change>
            <modified comment="Added version datatype to file_state version element. Altered oval:org.mitre.oval:ste:3811" date="2007-08-23T14:13:00.397-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="Added version datatype to file_state version element. Altered oval:org.mitre.oval:ste:3400" date="2007-08-23T14:13:00.076-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="Added version datatype to file_state version element. Altered oval:org.mitre.oval:ste:3654" date="2007-08-23T14:13:00.971-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="Added version datatype to file_state version element. Altered oval:org.mitre.oval:ste:3361" date="2007-08-23T14:13:00.510-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="Added version datatype to file_state version element. Altered oval:org.mitre.oval:ste:3590" date="2007-08-23T14:13:00.427-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="Added version datatype to file_state version element. Altered oval:org.mitre.oval:ste:3716" date="2007-08-23T14:13:00.118-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="Added version datatype to file_state version element. Altered oval:org.mitre.oval:ste:3653" date="2007-08-23T14:13:00.466-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-09-10T14:45:26.558-04:00">INTERIM</status_change>
            <status_change date="2007-09-27T08:57:44.470-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2109 - Correcting incorrect references to 64-bit Itanium XP." date="2012-08-23T17:47:00.168-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-08-23T17:53:06.548-04:00">INTERIM</status_change>
            <status_change date="2012-09-10T04:00:47.618-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:46.584-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:47.730-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 5.01,SP4 on Win2k,SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3854.1200" test_ref="oval:org.mitre.oval:tst:4193"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win 2k, SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1597" test_ref="oval:org.mitre.oval:tst:3205"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win XP SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2900.3157" test_ref="oval:org.mitre.oval:tst:3691"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win S03 SP1">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2954" test_ref="oval:org.mitre.oval:tst:4199"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win S03 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.4106" test_ref="oval:org.mitre.oval:tst:3218"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win XP SP1 (64-bit)">
          <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2954" test_ref="oval:org.mitre.oval:tst:4199"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win XP SP2 (64-bit)">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.4106" test_ref="oval:org.mitre.oval:tst:3218"/>
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 on Windows XP and S03">
          <criteria operator="OR" comment="Windows XP  or Server 2003 is installed">
            <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
            <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="the version of mshtml.dll is less than 7.0.6000.16525" test_ref="oval:org.mitre.oval:tst:3806"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 on Vista">
          <extend_definition comment="Microsoft Windows Vista is installed" definition_ref="oval:org.mitre.oval:def:228"/>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="the version of mshtml.dll is less than 7.0.6000.16527" test_ref="oval:org.mitre.oval:tst:3501"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2100" version="3" class="vulnerability">
      <metadata>
        <title>IE v5.5,SP2 Malformed GIF Image Double-free Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1048" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1048"/>
        <description>Double free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-08-02T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:47.923-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:42.119-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Software section">
        <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" test_ref="oval:org.mitre.oval:tst:3123"/>
        <criterion comment="the version of mshtml.dll is less than 5.50.4943.400" test_ref="oval:org.mitre.oval:tst:2762"/>
        <criterion negate="true" comment="the patch kb832894 is installed (Installed Components key)" test_ref="oval:org.mitre.oval:tst:2802"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:210" version="6" class="vulnerability" deprecated="true">
      <metadata>
        <title>DEPRECATED: Windows 2000 IIS HTTP Redirect Error Message Cross-site Scripting</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0075" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0075"/>
        <description>Cross-site scripting vulnerability for Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other web users via the error message used in a URL redirect (""302 Object Moved") message.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <modified comment="Multiple corrections and update to POSIX compatibility for ste:2884" date="2010-11-29T16:14:00.692-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-11-29T16:14:38.714-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:40.972-05:00">ACCEPTED</status_change>
            <modified comment="Use def:12346 instead" date="2011-01-20T10:18:24.960-05:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-01-20T10:18:24.960-05:00">DEPRECATED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="the version of w3svc.dll is less than 5.0.2195.5269" negate="false" test_ref="oval:org.mitre.oval:tst:3080"/>
        <criterion comment="Patch Q319733 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3095"/>
        <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
        <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
        <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3079"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2093" version="3" class="vulnerability">
      <metadata>
        <title>.NET PE Loader Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft .NET Framework</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0041" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0041"/>
        <description>The PE Loader service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to execute arbitrary code via unspecified vectors involving an "unchecked buffer" and unvalidated message lengths, probably a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-11T18:34:24">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-07-16T09:52:05.271-04:00">DRAFT</status_change>
            <modified comment="Removed Windows Vista criterion as this CVE does not affect Windows Vista" date="2007-07-16T14:03:00.474-04:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="Updated tst:3325 to use new obj:1808 to identify the .net 1.1 version of System.web.dll" date="2007-07-18T13:18:00.196-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <modified comment="Corrected obj:263 to use variable that constructs the path to the .net 1.1 directory." date="2007-07-18T13:42:00.929-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-08-02T14:47:15.684-04:00">INTERIM</status_change>
            <status_change date="2007-08-20T08:04:40.273-04:00">ACCEPTED</status_change>
            <modified comment="Corrected criteria to check for System.web.dll version is less than 2.0.50727.832 when looking for the vuln in .NET 2.0" date="2007-10-04T10:18:00.416-04:00">
              <contributor organization="Secure Elements, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2007-10-04T10:21:11.429-04:00">INTERIM</status_change>
            <status_change date="2007-10-22T08:53:26.873-04:00">ACCEPTED</status_change>
            <modified comment="Updated with the re-release of MS07-040 Bulletin" date="2008-03-26T10:51:02.210-04:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2008-03-31T04:00:21.943-04:00">INTERIM</status_change>
            <status_change date="2008-04-21T04:00:17.163-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
            <extend_definition comment="Microsoft Windows XP SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 1.0 (Service Pack 3 or later) is Installed" definition_ref="oval:org.mitre.oval:def:2136"/>
          <criterion comment="System.web.dll version is less than 1.0.3705.6060" test_ref="oval:org.mitre.oval:tst:4154"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
            <extend_definition comment="Microsoft Windows XP SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 1.1 Service Pack 1 is Installed" definition_ref="oval:org.mitre.oval:def:1834"/>
          <criterion comment="System.web.dll version is less than 1.1.4322.2407" test_ref="oval:org.mitre.oval:tst:3325"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
            <extend_definition comment="Microsoft Windows XP SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 (Original RTM or later) is installed" definition_ref="oval:org.mitre.oval:def:1934"/>
          <criterion comment="System.web.dll version is less than 2.0.50727.832" test_ref="oval:org.mitre.oval:tst:3378"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:209" version="6" class="vulnerability">
      <metadata>
        <title>SNMP Agent Service Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Simple Network Management Protocol (SNMP)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0053" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0053"/>
        <description>Buffer overflow in SNMP agent service in Windows 95/98/98SE, Windows NT 4.0, Windows 2000, and Windows XP allows remote attackers to cause a denial of service or execute arbitrary code via a malformed management request.  NOTE: this candidate may be split or merged with other candidates.  This and other PROTOS-related candidates, especially CVE-2002-0012 and CVE-2002-0013, will be updated when more accurate information is available.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-12-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified comment="Multiple corrections and update to POSIX compatibility for ste:2884" date="2010-11-29T16:14:00.692-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-11-29T16:14:39.517-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:40.678-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:44:45.632-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:02:22.564-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="the version of snmp.exe is less than 5.0.2195.4919" negate="false" test_ref="oval:org.mitre.oval:tst:2883"/>
          <criterion comment="Patch Q314147 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2959"/>
          <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3079"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the SNMP service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2958"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2088" version="3" class="vulnerability">
      <metadata>
        <title>Remote Code Execution Vulnerability in GDI</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3034" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3034"/>
        <description>Integer overflow in the AttemptWrite function in Graphics Rendering Engine (GDI) on Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted metafile (image) with a large record length value, which triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-15T09:28:35">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-08-15T15:55:13.524-04:00">DRAFT</status_change>
            <modified comment="Added version datatype to file_state version element. Altered oval:org.mitre.oval:ste:3518" date="2007-08-23T14:13:00.615-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="Added version datatype to file_state version element. Altered oval:org.mitre.oval:ste:3296" date="2007-08-23T14:13:00.851-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="Added version datatype to file_state version element. Altered oval:org.mitre.oval:ste:3068" date="2007-08-23T14:13:00.916-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-09-10T14:45:26.381-04:00">INTERIM</status_change>
            <status_change date="2007-09-27T08:57:43.686-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2088 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:06:18.034-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:26.447-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win2K,SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Gdi32.dll is less than 5.0.2195.7138" test_ref="oval:org.mitre.oval:tst:3211"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of Gdi32.dll is less than 5.1.2600.3159" test_ref="oval:org.mitre.oval:tst:3214"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP1 (64-bit)">
          <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="the version of Gdi32.dll is less than 5.2.3790.2960" test_ref="oval:org.mitre.oval:tst:3832"/>
        </criteria>
        <criteria operator="AND" comment="S03,SP1">
          <criteria operator="OR" comment="Microsoft Windows Server 2003 x64, Microsoft Windows Server 2003 SP1 x86/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP1 is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
          </criteria>
          <criterion comment="the version of Gdi32.dll is less than 5.2.3790.2960" test_ref="oval:org.mitre.oval:tst:3832"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2085" version="3" class="vulnerability">
      <metadata>
        <title>Content Disposition Parsing Cross Domain Information Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Outlook Express</product>
        </affected>
        <reference ref_id="CVE-2007-2227" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2227" source="CVE"/>
        <description>The MHTML protocol handler in Microsoft Outlook Express 6 and Windows Mail in Windows Vista does not properly handle Content-Disposition "notifications," which allows remote attackers to obtain sensitive information from other Internet Explorer domains, aka "Content Disposition Parsing Cross Domain Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2007-06-13T08:22:59.000-04:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-06-13T15:20:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-06-29T09:42:01.541-04:00">INTERIM</status_change>
            <status_change date="2007-07-16T09:55:13.933-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2085 - Correcting incorrect references to 64-bit Itanium XP." date="2012-08-23T17:47:00.168-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-08-23T17:52:14.538-04:00">INTERIM</status_change>
            <status_change date="2012-09-10T04:00:47.213-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Microsoft Outlook Express 6 on Win XP SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Microsoft Outlook Express 6.0 for Windows XP/2003 is installed" definition_ref="oval:org.mitre.oval:def:208"/>
          <criterion comment="the version of inetcomm.dll is less than 6.0.2900.3138" test_ref="oval:org.mitre.oval:tst:3908"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Outlook Express 6 on Win 2k3 SP1">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <extend_definition comment="Microsoft Outlook Express 6.0 for Windows XP/2003 is installed" definition_ref="oval:org.mitre.oval:def:208"/>
          <criterion comment="the version of inetcomm.dll is less than 6.0.3790.2929" test_ref="oval:org.mitre.oval:tst:3966"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Outlook Express 6 on Win 2k3 SP2">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <extend_definition comment="Microsoft Outlook Express 6.0 for Windows XP/2003 is installed" definition_ref="oval:org.mitre.oval:def:208"/>
          <criterion comment="the version of inetcomm.dll is less than 6.0.3790.4073" test_ref="oval:org.mitre.oval:tst:4092"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Outlook Express 6 on Win XP SP2 (64-bit)">
          <extend_definition comment="Microsoft Outlook Express 6.0 for Windows XP/2003 is installed" definition_ref="oval:org.mitre.oval:def:208"/>
          <criterion comment="the version of inetcomm.dll is less than 6.0.3790.4073" test_ref="oval:org.mitre.oval:tst:4092"/>
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Outlook Express 6 on Win XP SP1 (64-bit)">
          <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <extend_definition comment="Microsoft Outlook Express 6.0 for Windows XP/2003 is installed" definition_ref="oval:org.mitre.oval:def:208"/>
          <criterion comment="the version of inetcomm.dll is less than 6.0.3790.2929" test_ref="oval:org.mitre.oval:tst:3966"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2077" version="4" class="vulnerability">
      <metadata>
        <title>IE5.01,SP3 Content Advisor Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0555" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0555"/>
        <description>Buffer overflow in the Content Advisor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a crafted Content Advisor file, aka "Content Advisor Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-05-11T05:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2824. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:48:00.494-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:52:27.860-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:06.007-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:57.553-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:33.960-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3015"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3539.2400" negate="false" test_ref="oval:org.mitre.oval:tst:1083"/>
          <criterion comment="the patch kb890923  is installed (Win2K SP3  Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:1082"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2073" version="4" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP3 Drag-and-Drop Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0839" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0839"/>
        <description>Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by "wottapoop.html".</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-25T04:42:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-27T01:04:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-17T10:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2824. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:48:00.494-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:52:24.059-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:05.744-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:57.407-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:32.496-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3015"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3821.2800" negate="false" test_ref="oval:org.mitre.oval:tst:625"/>
          <criterion comment="the patch kb834707-ie501sp3 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:624"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2070" version="3" class="vulnerability">
      <metadata>
        <title>ASP.NET Null Byte Termination Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft .NET Framework</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0042" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0042"/>
        <description>Interpretation conflict in ASP.NET in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to access configuration files and obtain sensitive information, and possibly bypass security mechanisms that try to constrain the final substring of a string, via %00 characters, related to use of %00 as a string terminator within POSIX functions but a data character within .NET strings, aka "Null Byte Termination Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-11T18:34:24">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-07-16T09:52:05.810-04:00">DRAFT</status_change>
            <modified comment="Updated tst:3378 to use obj:4 to identify the .net 2.0 version of System.web.dll" date="2007-07-18T13:18:00.357-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <modified comment="Updated tst:3325 to use new obj:1808 to identify the .net 1.1 version of System.web.dll" date="2007-07-18T13:18:00.196-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <modified comment="Corrected obj:263 to use variable that constructs the path to the .net 1.1 directory." date="2007-07-18T13:42:00.929-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <modified comment="Changed obj:4 to use var:1061 instead of the duplicate var:998" date="2007-07-18T13:46:00.709-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-08-02T14:47:15.444-04:00">INTERIM</status_change>
            <status_change date="2007-08-20T08:04:40.098-04:00">ACCEPTED</status_change>
            <modified comment="Corrected criteria to check for System.web.dll version is less than 2.0.50727.832 when looking for the vuln in .NET 2.0" date="2007-10-04T10:18:00.780-04:00">
              <contributor organization="Secure Elements, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2007-10-04T10:21:28.811-04:00">INTERIM</status_change>
            <status_change date="2007-10-22T08:53:26.353-04:00">ACCEPTED</status_change>
            <modified comment="Updated with the re-release of MS07-040 Bulletin" date="2008-03-26T10:51:02.210-04:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2008-03-31T04:00:21.079-04:00">INTERIM</status_change>
            <status_change date="2008-04-21T04:00:16.347-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
            <extend_definition comment="Microsoft Windows XP SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Vista is installed" definition_ref="oval:org.mitre.oval:def:228"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 1.0 (Service Pack 3 or later) is Installed" definition_ref="oval:org.mitre.oval:def:2136"/>
          <criterion comment="System.web.dll version is less than 1.0.3705.6060" test_ref="oval:org.mitre.oval:tst:4154"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
            <extend_definition comment="Microsoft Windows XP SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Vista is installed" definition_ref="oval:org.mitre.oval:def:228"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 1.1 Service Pack 1 is Installed" definition_ref="oval:org.mitre.oval:def:1834"/>
          <criterion comment="System.web.dll version is less than 1.1.4322.2407" test_ref="oval:org.mitre.oval:tst:3325"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
            <extend_definition comment="Microsoft Windows XP SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 (Original RTM or later) is installed" definition_ref="oval:org.mitre.oval:def:1934"/>
          <criterion comment="System.web.dll version is less than 2.0.50727.832" test_ref="oval:org.mitre.oval:tst:3378"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Vista is installed" definition_ref="oval:org.mitre.oval:def:228"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 (Original RTM or later) is installed" definition_ref="oval:org.mitre.oval:def:1934"/>
          <criterion comment="System.web.dll version is less than 2.0.50727.832" test_ref="oval:org.mitre.oval:tst:3378"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2136" version="10" class="inventory">
      <metadata>
        <title>Microsoft .NET Framework 1.0 (Service Pack 3 or later) is Installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft .NET Framework 1.0</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:.net_framework:1.0"/>
        <description>Microsoft .NET Framework 1.0 (Service Pack 3 or later) is Installed</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-11T18:34:24">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-07-16T09:52:04.577-04:00">DRAFT</status_change>
            <status_change date="2007-08-01T22:26:16.025-04:00">INTERIM</status_change>
            <status_change date="2007-08-20T08:04:40.665-04:00">ACCEPTED</status_change>
            <status_change date="2007-09-13T11:07:56.167-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2136 - Updated to check registry keys instead of version of DLL." date="2011-01-13T14:14:00.592-05:00">
              <contributor organization="The MITRE Corporation">Nate Przybyszewski</contributor>
            </modified>
            <status_change date="2011-01-13T14:16:15.427-05:00">INTERIM</status_change>
            <status_change date="2011-01-31T04:00:14.636-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2136 - New Microsoft Patch Tuesday April 2012 definitions." date="2012-04-16T20:18:00.399-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2012-04-16T20:27:08.707-04:00">INTERIM</status_change>
            <status_change date="2012-05-07T04:02:44.385-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2136 - .NET Framework inventories with modified products." date="2014-03-18T14:31:00.962-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-18T14:33:24.286-04:00">INTERIM</status_change>
            <status_change date="2014-04-07T04:02:10.331-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2136 - added CPE references in several inventories for uniformity" date="2014-04-10T08:25:00.988-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-04-10T08:32:03.141-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:00:10.597-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Is the Microsoft .NET Framework 1.0 installed" test_ref="oval:org.mitre.oval:tst:292"/>
        <criteria operator="OR" comment=">.NET Framework 1.0 SP3">
          <criterion comment="Is the Microsoft .NET Framework 1.0 patched to SP3 or greater" test_ref="oval:org.mitre.oval:tst:42104"/>
          <criterion comment="Is the Microsoft .NET Framework 1.0 patched to SP3 or greater (XP MCE/Tablet)" test_ref="oval:org.mitre.oval:tst:42130"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1834" version="8" class="inventory">
      <metadata>
        <title>Microsoft .NET Framework 1.1 Service Pack 1 is Installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft .NET Framework 1.1</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:.net_framework:1.1:sp1"/>
        <description>Microsoft .NET Framework 1.1 Service Pack 1 is Installed</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-11T18:34:24">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-07-16T09:52:04.902-04:00">DRAFT</status_change>
            <status_change date="2007-08-01T22:26:14.747-04:00">INTERIM</status_change>
            <status_change date="2007-08-20T08:04:39.021-04:00">ACCEPTED</status_change>
            <status_change date="2007-09-13T11:07:56.030-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:412 - Updated to check registry keys instead of version of DLL." date="2011-01-13T14:14:00.592-05:00">
              <contributor organization="The MITRE Corporation">Nate Przybyszewski</contributor>
            </modified>
            <status_change date="2011-01-13T14:16:15.263-05:00">INTERIM</status_change>
            <status_change date="2011-01-31T04:00:13.982-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1834 - New Microsoft Patch Tuesday November 2012 definitions." date="2012-11-19T14:40:00.894-05:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-11-19T15:57:32.322-05:00">INTERIM</status_change>
            <status_change date="2012-12-10T04:00:28.511-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1834 - .NET Framework inventories with modified products." date="2014-03-18T14:31:00.962-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-18T14:33:24.486-04:00">INTERIM</status_change>
            <status_change date="2014-04-07T04:02:05.273-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Is the Microsoft .NET Framework 1.1 installed" test_ref="oval:org.mitre.oval:tst:412"/>
        <criterion comment="Is the Microsoft .NET Framework 1.1 patched to SP1" test_ref="oval:org.mitre.oval:tst:41951"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2063" version="3" class="vulnerability">
      <metadata>
        <title>Vulnerability in MSN Messenger and Windows Live Messenger Could Allow Remote Code Execution</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>MSN Messenger</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2931" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2931"/>
        <description>Heap-based buffer overflow in Microsoft MSN Messenger 6.2, 7.0, and 7.5, and Live Messenger 8.0 allows user-assisted remote attackers to execute arbitrary code via unspecified vectors involving video conversation handling in Web Cam and video chat sessions.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-09-25T05:47:58">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-09-27T08:47:04.534-04:00">DRAFT</status_change>
            <status_change date="2007-10-12T07:56:13.714-04:00">INTERIM</status_change>
            <status_change date="2007-10-28T20:27:11.414-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2063 - Updated def:2063 to include all Windows platforms vulnerable with MSN messenger 6.2, 7.0, 7.5 and Live messenger 8.0 installed." date="2011-01-31T17:20:00.048-05:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-01-31T17:20:45.715-05:00">INTERIM</status_change>
            <status_change date="2011-02-21T04:00:48.844-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="MSN Messenger on Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criteria operator="OR">
            <extend_definition comment="MSN Messenger 6.2 is installed" definition_ref="oval:org.mitre.oval:def:2187"/>
            <criteria operator="AND">
              <extend_definition comment="MSN Messenger 7.0 is installed" definition_ref="oval:org.mitre.oval:def:2047"/>
              <criterion comment="MSN Messenger 7.0, with version less than 7.0.0820.0 is installed" test_ref="oval:org.mitre.oval:tst:4167"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="MSN Messenger on all Windows platforms except Windows 2000">
          <extend_definition negate="true" comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <criteria operator="OR">
            <extend_definition comment="MSN Messenger 6.2 is installed" definition_ref="oval:org.mitre.oval:def:2187"/>
            <extend_definition comment="MSN Messenger 7.0 is installed" definition_ref="oval:org.mitre.oval:def:2047"/>
            <extend_definition comment="MSN Messenger 7.5 is installed" definition_ref="oval:org.mitre.oval:def:2087"/>
            <extend_definition comment="MSN Messenger 8.0 is installed" definition_ref="oval:org.mitre.oval:def:2209"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2209" version="7" class="inventory">
      <metadata>
        <title>MSN Messenger 8.0 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>MSN Messenger 8.0</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:msn_messenger:8.0"/>
        <description>MSN Messenger 8.0 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2007-09-25T05:47:58">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-09-27T08:47:04.491-04:00">DRAFT</status_change>
            <status_change date="2007-10-12T07:56:14.490-04:00">INTERIM</status_change>
            <status_change date="2007-10-28T20:27:12.150-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:4188 - Updated def:2209 to include a test for both MSN Messenger 8.0.0812 and MSN Messenger 8.0.0792" date="2011-03-08T13:15:00.082-05:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-03-08T13:19:46.516-05:00">INTERIM</status_change>
            <status_change date="2011-03-28T04:00:10.316-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2209 - Modifications vary from minor OVAL title/description changes to suggesting an alternative CPE name to use." date="2011-09-28T11:29:00.976-04:00">
              <contributor organization="The MITRE Corporation">David Rothenberg</contributor>
            </modified>
            <status_change date="2011-09-28T11:33:24.939-04:00">INTERIM</status_change>
            <status_change date="2011-10-17T04:00:17.848-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2209 - Modified MSN Messenger inventories: Fixed product version info" date="2015-04-10T10:01:00.091-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-04-10T10:03:14.144-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:11.131-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criterion comment="MSN Messenger 8.0.0812 is installed" test_ref="oval:org.mitre.oval:tst:4188"/>
        <criterion comment="MSN Messenger 8.0.0792 is installed" test_ref="oval:org.mitre.oval:tst:42193"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2187" version="5" class="inventory">
      <metadata>
        <title>MSN Messenger 6.2 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>MSN Messenger 6.2</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:msn_messenger:6.2"/>
        <description>MSN Messenger 6.2 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2007-09-25T05:47:58">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-09-27T08:47:03.757-04:00">DRAFT</status_change>
            <status_change date="2007-10-12T07:56:14.421-04:00">INTERIM</status_change>
            <status_change date="2007-10-28T20:27:11.996-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2187 - Modifications vary from minor OVAL title/description changes to suggesting an alternative CPE name to use." date="2011-09-28T11:29:00.976-04:00">
              <contributor organization="The MITRE Corporation">David Rothenberg</contributor>
            </modified>
            <status_change date="2011-09-28T11:33:22.699-04:00">INTERIM</status_change>
            <status_change date="2011-10-17T04:00:17.557-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2187 - Modified MSN Messenger inventories: Fixed product version info" date="2015-04-10T10:01:00.091-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-04-10T10:03:14.287-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:10.938-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="MSN Messenger 6.2 is installed" test_ref="oval:org.mitre.oval:tst:4055"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2087" version="5" class="inventory">
      <metadata>
        <title>MSN Messenger 7.5 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>MSN Messenger 7.5</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:msn_messenger:7.5"/>
        <description>MSN Messenger 7.5 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2007-09-25T05:47:58">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-09-27T08:47:04.432-04:00">DRAFT</status_change>
            <status_change date="2007-10-12T07:56:14.129-04:00">INTERIM</status_change>
            <status_change date="2007-10-28T20:27:11.697-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2087 - Modifications vary from minor OVAL title/description changes to suggesting an alternative CPE name to use." date="2011-09-28T11:29:00.976-04:00">
              <contributor organization="The MITRE Corporation">David Rothenberg</contributor>
            </modified>
            <status_change date="2011-09-28T11:33:16.314-04:00">INTERIM</status_change>
            <status_change date="2011-10-17T04:00:15.885-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2087 - Modified MSN Messenger inventories: Fixed product version info" date="2015-04-10T10:01:00.091-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-04-10T10:03:14.430-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:09.572-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="MSN Messenger 7.5 is installed" test_ref="oval:org.mitre.oval:tst:4242"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2047" version="5" class="inventory">
      <metadata>
        <title>MSN Messenger 7.0 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>MSN Messenger 7.0</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:msn_messenger:7.0"/>
        <description>MSN Messenger 7.0 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2007-09-25T05:47:58">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-09-27T08:47:03.858-04:00">DRAFT</status_change>
            <status_change date="2007-10-12T07:56:13.457-04:00">INTERIM</status_change>
            <status_change date="2007-10-28T20:27:11.135-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2047 - Modifications vary from minor OVAL title/description changes to suggesting an alternative CPE name to use." date="2011-09-28T11:29:00.976-04:00">
              <contributor organization="The MITRE Corporation">David Rothenberg</contributor>
            </modified>
            <status_change date="2011-09-28T11:33:19.649-04:00">INTERIM</status_change>
            <status_change date="2011-10-17T04:00:15.188-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2047 - Modified MSN Messenger inventories: Fixed product version info" date="2015-04-10T10:01:00.091-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-04-10T10:03:13.973-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:09.385-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="MSN Messenger 7.0 is installed" test_ref="oval:org.mitre.oval:tst:4098"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:206" version="4" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP2 Malformed GIF Image Double-free Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1048" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1048"/>
        <description>Double free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-08-02T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2868. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:41:00.387-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:43:11.217-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:04.806-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:53.420-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:28.945-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Software section">
        <criterion comment="Internet Explorer 5.01 Service Pack 2 is installed" test_ref="oval:org.mitre.oval:tst:3063"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3532.300" test_ref="oval:org.mitre.oval:tst:2803"/>
        <criterion negate="true" comment="the patch kb832894 is installed (Installed Components key)" test_ref="oval:org.mitre.oval:tst:2802"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2056" version="3" class="vulnerability">
      <metadata>
        <title>GDI Local Elevation of Privilege Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5758" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5758"/>
        <description>The Graphics Rendering Engine in Microsoft Windows 2000 through 2000 SP4 and Windows XP through SP2 maps GDI Kernel structures on a global shared memory section that is mapped with read-only permissions, but can be remapped by other processes as read-write, which allows local users to cause a denial of service (memory corruption and crash) and gain privileges by modifying the kernel structures.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-04-09T09:49:32">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-04-09T11:20:00.000-05:00">DRAFT</status_change>
            <status_change date="2007-04-25T19:52:22.945-04:00">INTERIM</status_change>
            <modified comment="Removed criteria sections and affected.platform elements for S03 and Vista. MS07-017 says they are not affected." date="2007-04-26T14:26:00.398-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-05-23T15:05:38.912-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2056 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:06:43.317-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:26.130-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="gdi32.dll version is less than 5.0.2195.7133" test_ref="oval:org.mitre.oval:tst:3337"/>
        </criteria>
        <criteria operator="AND" comment="Windows XP SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="gdi32.dll version is less than 5.1.2600.3099" test_ref="oval:org.mitre.oval:tst:3215"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2055" class="vulnerability" version="1">
      <metadata>
        <title>Vulnerability in Crystal Reports for Microsoft Visual Studio Could Allow Remote Code Execution</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Visual Studio</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-6133" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6133"/>
        <description>Stack-based buffer overflow in Visual Studio Crystal Reports for Microsoft Visual Studio .NET 2002 and 2002 SP1, .NET 2003 and 2003 SP1, and 2005 and 2005 SP1 (formerly Business Objects Crystal Reports XI Professional) allows user-assisted remote attackers to execute arbitrary code via a crafted RPT file.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-09-25T05:47:58">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-09-27T08:47:05.208-04:00">DRAFT</status_change>
            <modified comment="set datatype to version on file state 2972" date="2007-10-04T12:11:00.241-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="set datatype to version on file state 3261" date="2007-10-04T12:11:00.500-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-10-22T08:53:25.962-04:00">INTERIM</status_change>
            <status_change date="2007-11-06T12:26:41.959-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment=".NET 2002, SP1">
          <extend_definition comment="Microsoft Visual Studio .NET 2002,SP1 is installed" definition_ref="oval:org.mitre.oval:def:981"/>
          <criterion comment="the version of crpe32.dll is less than 9.1.2.1871" test_ref="oval:org.mitre.oval:tst:4172"/>
        </criteria>
        <criteria operator="AND" comment=".NET 2003">
          <extend_definition comment="Microsoft Visual Studio .NET 2003 is installed" definition_ref="oval:org.mitre.oval:def:166"/>
          <criterion comment="the version of crpe32.dll is less than 9.1.2.1871" test_ref="oval:org.mitre.oval:tst:4172"/>
        </criteria>
        <criteria operator="AND" comment=".NET 2003">
          <extend_definition comment="Microsoft Visual Studio .NET 2005 is installed" definition_ref="oval:org.mitre.oval:def:426"/>
          <criterion comment="the version of crpe32.dll is less than 10.2.0.1222" test_ref="oval:org.mitre.oval:tst:3483"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:426" version="9" class="inventory">
      <metadata>
        <title>Microsoft Visual Studio 2005 is installed.</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Visual Studio 2005</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:visual_studio:2005"/>
        <description>Microsoft Visual Studio 2005 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-12-13T08:17:04">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-12-14T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:53:56.869-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:31.985-05:00">ACCEPTED</status_change>
            <modified date="2008-03-02T04:44:54" comment="Added file check to ensure a full installation.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2008-03-17T04:00:21.372-04:00">ACCEPTED</status_change>
            <modified comment="Added the CPE name and added platform for vista" date="2009-05-26T16:45:00.332-04:00">
              <contributor organization="The MITRE Corporation">Brendan Miles</contributor>
            </modified>
            <status_change date="2009-05-25T10:32:00.713-04:00">INTERIM</status_change>
            <status_change date="2009-06-15T04:00:38.387-04:00">ACCEPTED</status_change>
            <modified comment="Added Microsoft Windows Server 2008 platform" date="2009-09-27T16:45:00.332-04:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2009-10-05T04:00:09.737-04:00">INTERIM</status_change>
            <status_change date="2009-10-26T04:00:03.240-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:48.806-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:48.806-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:02.227-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:426 - The attached file contains modified inventory for Microsoft Visual Studio." date="2013-04-15T20:51:00.845-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-04-15T20:56:48.989-04:00">INTERIM</status_change>
            <status_change date="2013-05-06T04:02:40.457-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="devenv.exe exists as a Microsoft Visual Studio 2005 component" test_ref="oval:org.mitre.oval:tst:7741"/>
        <criterion comment="Check if HKLM\Software\Microsoft\VisualStudio\8.0!InstallDir exists" test_ref="oval:org.mitre.oval:tst:80280"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2054" class="vulnerability" version="2">
      <metadata>
        <title>IMAP Literal Processing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Exchange Server</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0221" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0221"/>
        <description>Integer overflow in the IMAP (IMAP4) support in Microsoft Exchange Server 2000 SP3 allows remote attackers to cause a denial of service (service hang) via crafted literals in an IMAP command, aka the "IMAP Literal Processing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2007-05-09T10:04:48">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-05-09T12:53:06-04:00">DRAFT</status_change>
            <status_change date="2007-05-31T15:26:39.721-04:00">INTERIM</status_change>
            <status_change date="2007-06-15T11:07:38.252-04:00">ACCEPTED</status_change>
            <modified comment="References registry value for Common Files directory due to multilingual support" date="2008-04-14T11:07:00.679-04:00">
              <contributor organization="GFI Software">Clifford Farrugia</contributor>
            </modified>
            <status_change date="2008-04-14T12:26:44.754-04:00">INTERIM</status_change>
            <status_change date="2008-05-05T04:00:16.603-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Microsoft Exchange 2000 Server Service Pack 3" operator="AND">
        <extend_definition comment="Microsoft Exchange 2000 Server Service Pack 3 is installed" definition_ref="oval:org.mitre.oval:def:1858"/>
        <criterion comment="the version of Cdoex.dll is less than 6.0.6619.12" test_ref="oval:org.mitre.oval:tst:3975"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2048" version="3" class="vulnerability">
      <metadata>
        <title>HTML Objects Memory Corruption Vulnerabilities</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0947" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0947"/>
        <description>Use-after-free vulnerability in Microsoft Internet Explorer 7 on Windows XP SP2, Windows Server 2003 SP1 or SP2, or Windows Vista allows remote attackers to execute arbitrary code via crafted HTML objects, resulting in accessing deallocated memory of CMarkup objects, aka the second of two "HTML Objects Memory Corruption Vulnerabilities" and a different issue than CVE-2007-0946.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-05-08T19:30:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-05-09T12:53:06-04:00">DRAFT</status_change>
            <status_change date="2007-05-31T15:26:39.021-04:00">INTERIM</status_change>
            <modified comment="Corrected version of ste:3224. Implemented by Jon Baker of the MITRE Corporation." date="2007-06-04T08:42:00.584-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <modified comment="Corrected criteria on 64 bit check" date="2007-06-07T08:42:00.584-04:00">
              <contributor organization="Secure Elements, Inc.">Jeff Ito</contributor>
            </modified>
            <status_change date="2007-06-22T08:57:42.928-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3877 - modified comments" date="2014-02-28T15:13:00.247-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-28T15:16:16.776-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:15.381-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="IE 5.01,SP4 on Win2k,SP4" operator="AND">
          <extend_definition comment="Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Internet Explorer 5.01, SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3850.1900" test_ref="oval:org.mitre.oval:tst:3859"/>
        </criteria>
        <criteria comment="IE 6 on Windows 2000" operator="AND">
          <extend_definition comment="Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1593" test_ref="oval:org.mitre.oval:tst:3454"/>
        </criteria>
        <criteria comment="IE 6 on Windows XP SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1593" test_ref="oval:org.mitre.oval:tst:3454"/>
        </criteria>
        <criteria comment="XP,SP1 (64-bit) and Server 2003, SP1 (IE6)" operator="AND">
          <criteria operator="OR" comment="Windows XP (64-bit,SP1) or Server 2003 (SP1) is installed">
            <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          </criteria>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2885" test_ref="oval:org.mitre.oval:tst:3810"/>
        </criteria>
        <criteria comment="XP,SP2 (64-bit) and Server 2003, SP2 (IE6)" operator="AND">
          <criteria operator="OR" comment="Windows XP (64-bit,SP2) or Server 2003 (SP1) is installed">
            <criteria operator="AND" comment="Windows XP (64-bit,SP2) is installed">
              <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
              <criterion comment="64-Bit version of Windows is installed" test_ref="oval:org.mitre.oval:tst:2744"/>
            </criteria>
            <extend_definition comment="Windows Server 2003, SP2 is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          </criteria>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.4026" test_ref="oval:org.mitre.oval:tst:3176"/>
        </criteria>
        <criteria comment="IE 7 on Windows XP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="the version of Ieapfltr.dll is less than 7.0.6000.16432" test_ref="oval:org.mitre.oval:tst:3877"/>
        </criteria>
        <criteria comment="Windows Server 2003 Service Pack 1 version" operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 (x86) SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of Ieapfltr.dll is less than 7.0.6000.16432" test_ref="oval:org.mitre.oval:tst:3877"/>
        </criteria>
        <criteria comment="Windows Server 2003 Service Pack 2 version" operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <criterion comment="the version of Ieapfltr.dll is less than 7.0.6000.16432" test_ref="oval:org.mitre.oval:tst:3877"/>
        </criteria>
        <criteria comment="IE 7 on Windows Vista" operator="AND">
          <extend_definition comment="Windows Vista is installed" definition_ref="oval:org.mitre.oval:def:228"/>
          <criterion comment="the version of mshtml.dll is less than 7.0.6000.20547" test_ref="oval:org.mitre.oval:tst:3334"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2046" version="6" class="vulnerability">
      <metadata>
        <title>Windows 2000 Drag-and-Drop Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0053" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0053"/>
        <description>Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the "Drag-and-Drop Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-31T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-04-12T08:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed test to check kb890047.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.795-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-10-25T16:47:48.826-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:01:06.090-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:46.357-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:02:20.658-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or earlier) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1247"/>
          <criterion comment="the version of shell32.dll is less than 5.0.3900.7009" negate="false" test_ref="oval:org.mitre.oval:tst:632"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Drag-and-Drop disabled when set to 3" negate="true" test_ref="oval:org.mitre.oval:tst:1316"/>
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2045" version="3" class="vulnerability">
      <metadata>
        <title>URL Parsing Cross Domain Information Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Outlook Express</product>
        </affected>
        <reference ref_id="CVE-2007-2225" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2225" source="CVE"/>
        <description>A component in Microsoft Outlook Express 6 and Windows Mail in Windows Vista does not properly handle certain HTTP headers when processing MHTML protocol URLs, which allows remote attackers to obtain sensitive information from other Internet Explorer domains, aka "URL Parsing Cross Domain Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2007-06-13T08:22:59.000-04:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-06-13T15:20:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-06-29T09:42:00.986-04:00">INTERIM</status_change>
            <status_change date="2007-07-16T09:55:12.887-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2045 - Correcting incorrect references to 64-bit Itanium XP." date="2012-08-23T17:47:00.168-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-08-23T17:52:54.434-04:00">INTERIM</status_change>
            <status_change date="2012-09-10T04:00:46.413-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Microsoft Outlook Express 6 on Win XP SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Microsoft Outlook Express 6.0 for Windows XP/2003 is installed" definition_ref="oval:org.mitre.oval:def:208"/>
          <criterion comment="the version of inetcomm.dll is less than 6.0.2900.3138" test_ref="oval:org.mitre.oval:tst:3908"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Outlook Express 6 on Win 2k3 SP1">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <extend_definition comment="Microsoft Outlook Express 6.0 for Windows XP/2003 is installed" definition_ref="oval:org.mitre.oval:def:208"/>
          <criterion comment="the version of inetcomm.dll is less than 6.0.3790.2929" test_ref="oval:org.mitre.oval:tst:3966"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Outlook Express 6 on Win 2k3 SP2">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <extend_definition comment="Microsoft Outlook Express 6.0 for Windows XP/2003 is installed" definition_ref="oval:org.mitre.oval:def:208"/>
          <criterion comment="the version of inetcomm.dll is less than 6.0.3790.4073" test_ref="oval:org.mitre.oval:tst:4092"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Outlook Express 6 on Win XP SP2 (64-bit)">
          <extend_definition comment="Microsoft Outlook Express 6.0 for Windows XP/2003 is installed" definition_ref="oval:org.mitre.oval:def:208"/>
          <criterion comment="the version of inetcomm.dll is less than 6.0.3790.4073" test_ref="oval:org.mitre.oval:tst:4092"/>
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Outlook Express 6 on Win XP SP1 (64-bit)">
          <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <extend_definition comment="Microsoft Outlook Express 6.0 for Windows XP/2003 is installed" definition_ref="oval:org.mitre.oval:def:208"/>
          <criterion comment="the version of inetcomm.dll is less than 6.0.3790.2929" test_ref="oval:org.mitre.oval:tst:3966"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:204" version="5" class="vulnerability">
      <metadata>
        <title>IE ActiveX Popup Zone Restriction Bypass</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0838" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0838"/>
        <description>Internet Explorer allows remote attackers to bypass zone restrictions to inject and execute arbitrary programs by creating a popup window and inserting ActiveX object code with a "data" tag pointing to the malicious code, which Internet Explorer treats as HTML or Javascript, but later executes as an HTA application, a different vulnerability than CVE-2003-0532, and as exploited using the QHosts Trojan horse (aka Trojan.Qhosts, QHosts-1, VBS.QHOSTS, or aolfix.exe).</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T05:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2004-03-04T05:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-25T05:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="modified wrt-18 - Changed value element to include pattern match">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:45:58.888-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:04.584-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:53.836-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:27.219-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Internet Explorer 6.0 or IE 6.0 SP1 is installed">
            <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
            <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          </criteria>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1264" negate="false" test_ref="oval:org.mitre.oval:tst:2918"/>
          <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
            </criteria>
          </criteria>
          <criterion comment=".hta applications are enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2915"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2034" version="6" class="vulnerability">
      <metadata>
        <title>Microsoft Agent URL Parsing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1205" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1205"/>
        <description>Unspecified vulnerability in Microsoft Agent (msagent\agentsvr.exe) in Windows 2000 SP4, XP SP2, and Server 2003, 2003 SP1, and 2003 SP2 allows remote attackers to execute arbitrary code via crafted URLs, which result in memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-04-10T16:31:02">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-04-10T16:31:02.000-05:00">DRAFT</status_change>
            <status_change date="2007-04-25T19:52:22.689-04:00">INTERIM</status_change>
            <status_change date="2007-05-23T15:05:37.577-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2034 - Corrected missing platforms and file versions" date="2011-04-07T11:23:00.405-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-04-07T11:24:17.205-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2034 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-09T04:01:25.270-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2034 - Correcting incorrect references to 64-bit Itanium XP." date="2012-08-23T17:47:00.168-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-08-23T17:52:10.441-04:00">INTERIM</status_change>
            <status_change date="2012-09-10T04:00:45.839-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows 2000 SP4, Windows Server 2003 x86/x64/ia64, Windows XP SP2 x86 and Agentdpv.dll version is less than 2.0.0.3425">
          <criteria operator="OR" comment="Windows 2000 SP4, Windows Server 2003 x86/x64/ia64, Windows XP SP2 x86">
            <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x86) Gold is installed" definition_ref="oval:org.mitre.oval:def:165"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          </criteria>
          <criterion comment="The version of Agentdpv.dll is less than 2.0.0.3425." test_ref="oval:org.mitre.oval:tst:4156"/>
        </criteria>
        <criteria operator="AND" comment="Windows Server 2003 Service Pack 2 x86/x64/ia64, Windows Server 2003 SP1, Windows XP SP1/SP2 x64 and Agentdpv.dll version is less than 5.2.3790.1243">
          <criteria operator="OR" comment="Windows Server 2003 Service Pack 2 x86/x64/ia64, Windows Server 2003 SP1, Windows XP SP1/SP2 x64">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          </criteria>
          <criterion comment="The version of Agentdpv.dll is less than 5.2.3790.1243." test_ref="oval:org.mitre.oval:tst:3462"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2031" version="7" class="vulnerability">
      <metadata>
        <title>Speech Control Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference ref_id="CVE-2007-2222" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2222" source="CVE"/>
        <description>Multiple buffer overflows in the (1) ActiveListen (Xlisten.dll) and (2) ActiveVoice (Xvoice.dll) speech controls, as used by Microsoft Internet Explorer 5.01, 6, and 7, allow remote attackers to execute arbitrary code via a crafted ActiveX object that triggers memory corruption, as demonstrated via the ModeName parameter to the FindEngine function in ACTIVEVOICEPROJECTLib.DirectSS.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-06-13T08:22:59.000-04:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-06-13T15:20:00.000-04:00">DRAFT</status_change>
            <modified comment="Added Vista as an affected platform." date="2007-06-16T11:52:00.571-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-07-03T14:05:58.841-04:00">INTERIM</status_change>
            <status_change date="2007-07-18T15:57:52.584-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2031 - Updates made to criteria user correct IDs and comments." date="2011-01-07T14:47:00.406-05:00">
              <contributor organization="G2, Inc.">Jeff Cockerill</contributor>
            </modified>
            <status_change date="2011-01-07T14:50:07.332-05:00">INTERIM</status_change>
            <status_change date="2011-01-24T04:00:32.547-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2031 - Correcting incorrect references to 64-bit Itanium XP." date="2012-08-23T17:47:00.168-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-08-23T17:52:50.159-04:00">INTERIM</status_change>
            <status_change date="2012-09-10T04:00:45.234-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:50.344-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:26.798-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 5.01,SP4 on Win2k,SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="the version of Mshtml.dll is less than 5.0.3853.3000" test_ref="oval:org.mitre.oval:tst:3507"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win 2k, SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the version of Mshtml.dll is less than 6.0.2800.1595" test_ref="oval:org.mitre.oval:tst:3202"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win XP SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of Mshtml.dll is less than 6.0.2900.3132" test_ref="oval:org.mitre.oval:tst:3224"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win 2k3 SP1">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of Mshtml.dll is less than 6.0.3790.2920" test_ref="oval:org.mitre.oval:tst:3899"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win 2k3 SP2">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of Mshtml.dll is less than 6.0.3790.4064" test_ref="oval:org.mitre.oval:tst:3773"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 on Win XP SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="the version of Mshtml.dll is less than 7.0.6000.16481" test_ref="oval:org.mitre.oval:tst:3781"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 on Win 2k3 SP1 or SP2">
          <criteria operator="OR" comment="Win 2k3 SP1 or SP2">
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="the version of Mshtml.dll is less than 7.0.6000.16481" test_ref="oval:org.mitre.oval:tst:3781"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 on Win Vista">
          <extend_definition comment="Microsoft Windows Vista is installed" definition_ref="oval:org.mitre.oval:def:228"/>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="the version of Mshtml.dll is less than 7.0.6000.16481" test_ref="oval:org.mitre.oval:tst:3781"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win XP SP2 (64-bit)">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of Mshtml.dll is less than 6.0.3790.4064" test_ref="oval:org.mitre.oval:tst:3773"/>
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win XP SP1 (64-bit)">
          <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of Mshtml.dll is less than 6.0.3790.2920" test_ref="oval:org.mitre.oval:tst:3899"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 on Win XP SP2 (64-bit)">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="the version of Mshtml.dll is less than 7.0.6000.16481" test_ref="oval:org.mitre.oval:tst:3781"/>
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:203" version="4" class="vulnerability">
      <metadata>
        <title>IE v6.0 Frames Cross-site Scripting Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1187" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1187"/>
        <description>Cross-site scripting vulnerability (XSS) in Internet Explorer 5.01 through 6.0 allows remote attackers to read and execute files on the local system via web pages using the &lt;frame> or &lt;iframe> element and javascript, aka "Frames Cross Site Scripting," as demonstrated using the PrivacyPolicy.dlg resource.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-27T05:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-03-09T05:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Changed IE registry test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:53.978-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:26.679-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the version of mshtml.dll is less than 6.0.2722.900" negate="false" test_ref="oval:org.mitre.oval:tst:2884"/>
        <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
        <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
        <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2020" version="3" class="vulnerability">
      <metadata>
        <title>Mozilla Accessing XBL Compilation Scope via valueOf.call()</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1733" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1733"/>
        <description>Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 does not properly protect the compilation scope of privileged built-in XBL bindings, which allows remote attackers to execute arbitrary code via the (1) valueOf.call or (2) valueOf.apply methods of an XBL binding, or (3) "by inserting an XBL method into the DOM's document.body prototype chain."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-07T09:05:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:42.962-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:1133" date="2007-02-26T08:08:00.208-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-26T08:09:15.851-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:1135" date="2007-02-26T08:21:00.993-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:1136" date="2007-02-26T08:24:00.848-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:1138" date="2007-02-26T08:25:00.405-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:2283" date="2007-02-26T08:29:00.407-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:2284" date="2007-02-26T08:30:00.724-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:17:10.898-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:881" date="2007-04-23T12:05:00.811-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:12:54.039-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:882" date="2007-04-23T12:05:00.939-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in obj:883" date="2007-04-23T12:05:00.804-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in obj:1385" date="2007-04-23T12:05:00.430-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:11:04.533-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1268"/>
          <criterion comment="Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1267"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Thunderbird version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1266"/>
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1265"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.12 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1264"/>
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1263"/>
        </criteria>
        <criteria operator="AND" comment="A pre-release of SeaMonkey 1.0 is installed">
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2439"/>
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2438"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2013" version="8" class="vulnerability">
      <metadata>
        <title>CSRSS DoS Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-6797" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6797"/>
        <description>The Client Server Run-Time Subsystem (CSRSS) in Microsoft Windows allows local users to cause a denial of service (crash) or read arbitrary memory from csrss.exe via crafted arguments to the NtRaiseHardError function with status 0x50000018, a different vulnerability than CVE-2006-6696.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-04-10T16:31:02">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-04-10T16:31:02.000-05:00">DRAFT</status_change>
            <status_change date="2007-04-25T19:52:22.385-04:00">INTERIM</status_change>
            <modified comment="Fixed typo in Vista criteria block: changed reference to extended def:521 (XP SP2) to def:228 (Vista)." date="2007-04-26T11:10:00.426-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <modified comment="Fixed the version of winsrv.dll to 6.0.6000.16445 for Vista." date="2007-05-03T15:48:00.375-04:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2007-05-23T15:05:36.689-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2013 - Update to MS07-021" date="2011-04-07T11:19:00.389-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-04-07T11:21:43.141-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2013 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-09T04:01:24.631-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2013 - Correcting incorrect references to 64-bit Itanium XP." date="2012-08-23T17:47:00.168-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-08-23T17:52:53.557-04:00">INTERIM</status_change>
            <status_change date="2012-09-10T04:00:44.566-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2013 - Multiple updates to several Windows OVAL entities. Includes CPE, title, and description updates. Fixed incorrectly referenced criteria. Added new criteria, fixed criteria checks, and improved criteria comments for several definitions." date="2012-11-02T20:20:00.882-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-11-02T20:24:53.917-04:00">INTERIM</status_change>
            <status_change date="2012-11-19T04:00:33.510-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="The version of winsrv.dll is less than 5.0.2195.7135." test_ref="oval:org.mitre.oval:tst:3935"/>
        </criteria>
        <criteria operator="AND" comment="Windows XP SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="The version of winsrv.dll is less than 5.1.2600.3103." test_ref="oval:org.mitre.oval:tst:42142"/>
        </criteria>
        <criteria operator="AND" comment="Windows XP SP1 x64">
          <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="The version of winsrv.dll is less than 5.2.3790.2902." test_ref="oval:org.mitre.oval:tst:3229"/>
        </criteria>
        <criteria operator="AND" comment="Windows XP SP2 x64">
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          <criterion comment="The version of winsrv.dll is less than 5.2.3790.4043." test_ref="oval:org.mitre.oval:tst:80250"/>
        </criteria>
        <criteria operator="AND" comment="Windows Server 2003 Gold versions">
          <criteria operator="OR" comment="Windows Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (x86) Gold is installed" definition_ref="oval:org.mitre.oval:def:165"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <criterion comment="The version of winsrv.dll is less than 5.2.3790.658." test_ref="oval:org.mitre.oval:tst:3288"/>
        </criteria>
        <criteria operator="AND" comment="Windows Server 2003 SP1 versions">
          <criteria operator="OR" comment="Windows Server 2003 x86/x64/ia64 SP1">
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:4386"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
          </criteria>
          <criterion comment="The version of winsrv.dll is less than 5.2.3790.2902." test_ref="oval:org.mitre.oval:tst:3229"/>
        </criteria>
        <criteria operator="AND" comment="Windows Server 2003 Service Pack 2 x86/x64/ia64 and winsrv.dll">
          <criteria operator="OR" comment="Windows Server 2003 Service Pack 2 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="The version of winsrv.dll is less than 5.2.3790.4043." test_ref="oval:org.mitre.oval:tst:80250"/>
        </criteria>
        <criteria operator="AND" comment="Windows Vista">
          <criteria operator="OR" comment="Windows Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista is installed" definition_ref="oval:org.mitre.oval:def:228"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="GRD/LDR version Check">
            <criterion comment="The version of winsrv.dll is less than 6.0.6000.16445." test_ref="oval:org.mitre.oval:tst:3701"/>
            <criteria operator="AND" comment="LDR version check">
              <criterion comment="the version of winsrv.dll is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:80223"/>
              <criterion comment="the version of winsrv.dll is less than 6.0.6000.20544" test_ref="oval:org.mitre.oval:tst:79826"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2012" version="1" class="vulnerability">
      <metadata>
        <title>Windows Active Directory Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0040" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0040"/>
        <description>The LDAP service in Windows Active Directory in Microsoft Windows 2000 Server SP4, Server 2003 SP1 and SP2, Server 2003 x64 Edition and SP2, and Server 2003 for Itanium-based Systems SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted LDAP request with an unspecified number of "convertible attributes."</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-10T18:34:24">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-07-11T14:48:25.147-04:00">DRAFT</status_change>
            <status_change date="2007-08-01T22:26:15.284-04:00">INTERIM</status_change>
            <status_change date="2007-08-20T08:04:39.839-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Windows 2000 SP4" operator="AND">
          <extend_definition comment="Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="ntdsa.dll version is less than 5.0.2195.7135" test_ref="oval:org.mitre.oval:tst:3970"/>
        </criteria>
        <criteria comment="Windows 2003 SP1" operator="AND">
          <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="ntdsa.dll version is less than 5.2.3790.2926" test_ref="oval:org.mitre.oval:tst:3752"/>
        </criteria>
        <criteria comment="Windows 2003 SP2" operator="AND">
          <extend_definition comment="Windows Server 2003, SP2 is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <criterion comment="ntdsa.dll version is less than 5.2.3790.4070" test_ref="oval:org.mitre.oval:tst:3944"/>
        </criteria>
        <criteria comment="Windows 2003 x64" operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          <criterion comment="ntdsa.dll version is less than 5.2.3790.2926" test_ref="oval:org.mitre.oval:tst:3752"/>
        </criteria>
        <criteria comment="Windows 2003 SP2 x64" operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 (x64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
          <criterion comment="ntdsa.dll version is less than 5.2.3790.4070" test_ref="oval:org.mitre.oval:tst:3944"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:200" version="7" class="vulnerability" deprecated="true">
      <metadata>
        <title>DEPRECATED: Windows Script Engine Heap Overflow (Test 1)</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Windows Script Engine for JScript v5.6</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0010" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0010"/>
        <description>Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows operating system allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail that uses a large array index value that enables a heap-based buffer overflow attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-27T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2004-03-03T12:00:00.000-04:00" comment="Corrected to reflect the unification of the Windows Schema">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if active scripting is enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </modified>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2004-08-24T10:58:00.000-04:00" comment="Added Patch to Definition">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2004-08-24T10:58:00.000-04:00" comment="negated patch">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-08-26T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-07-03T12:56:00.000-04:00" comment="Added negate=true attribute to criteria sub-block to fix conversion error from OVAL 4.2 to OVAL 5.0">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-07-03T12:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:11.933-04:00">ACCEPTED</status_change>
            <modified comment="Fixed regex in ste:2889.  Implemented by Matthew Wojcik." date="2007-03-06T18:19:00.507-05:00">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2007-03-06T18:21:11.452-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:10.592-04:00">ACCEPTED</status_change>
            <modified comment="Use def:134 instead, which covers all appropriate versions of windows and uses the file test" date="2011-01-20T10:33:54.035-05:00">
              <contributor organization="The MITRE Corporation">Nate Przybyszewski</contributor>
            </modified>
            <status_change date="2011-01-20T10:33:54.035-05:00">DEPRECATED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="the version of jscript.dll is less than 5.6.0.8513" negate="false" test_ref="oval:org.mitre.oval:tst:2905"/>
          <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed" negate="true">
            <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
            <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
          </criteria>
          <criterion comment="the patch js56nen.exe (5.6.0.8513 version) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2904"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="active scripting is enabled">
            <criteria operator="AND" comment="current user settings are being used and active scripting is enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and active scripting is enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20" version="2" class="vulnerability" deprecated="true">
      <metadata>
        <title>Suppressed OVAL20</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Distributed Component Object Model (DCOM)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0715" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0715"/>
        <description>Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed DCERPC DCOM object activation request packet with modified length fields, a different vulnerability than CVE-2003-0352 (Blaster/Nachi) and CVE-2003-0528.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-11-02T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-11-03T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-12-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-01-06T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-06-08T03:17:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-29T06:49:00.000-04:00">ACCEPTED</status_change>
            <modified date="2007-03-01T12:01:01" comment="Deprecated in favor of oval:org.mitre.oval:def:264.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-03-01T12:01:01">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="the version of rpcss.dll is less than 5.0.2195.6810" negate="false" test_ref="oval:org.mitre.oval:tst:3083"/>
        <criterion comment="the patch kb824146 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:3082"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1990" version="7" class="vulnerability">
      <metadata>
        <title>MSDTC Denial of Service Vulnerability (Win2K)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1184" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1184"/>
        <description>Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0, 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to cause a denial of service (crash) via a BuildContextW request with a large (1) UuidString or (2) GuidIn of a certain length, which causes an out-of-range memory access, aka the MSDTC Denial of Service Vulnerability.  NOTE: this is a variant of CVE-2005-2119.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-10T03:16:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:41.999-04:00">ACCEPTED</status_change>
            <modified comment="Fixed regex in ste:2889.  Implemented by Matthew Wojcik." date="2007-03-06T18:19:00.507-05:00">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2007-03-06T18:21:08.822-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:10.429-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1990 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:06:29.380-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:02:15.392-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="the version of Msdtctm.dll is less than 2000.2.3535.0" test_ref="oval:org.mitre.oval:tst:1074"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:199" version="8" class="vulnerability">
      <metadata>
        <title>Weak Encryption in RDP Protocol</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Remote Data Protocol (RDP)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0863" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0863"/>
        <description>Remote Data Protocol (RDP) version 5.0 in Microsoft Windows 2000 and RDP 5.1 in Windows XP does not encrypt the checksums of plaintext session data, which could allow a remote attacker to determine the contents of encrypted sessions via sniffing, aka "Weak Encryption in RDP Protocol."</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2005-03-07T12:00:00.000-04:00" comment="modified wrt-222 - changed pattern match">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-03-09T07:55:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-29T07:59:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Multiple corrections and update to POSIX compatibility for ste:2878" date="2010-11-29T16:13:00.904-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-11-29T16:14:04.221-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:39.390-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:07.963-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:02:14.604-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:2636 - Definitions for numerous CVEs" date="2012-03-27T14:22:00.237-04:00">
              <contributor organization="DTCC">Scott Quint</contributor>
            </modified>
            <status_change date="2012-03-27T14:37:33.872-04:00">INTERIM</status_change>
            <status_change date="2012-04-16T04:07:56.223-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Terminal Server Version" negate="false" test_ref="oval:org.mitre.oval:tst:2816"/>
          <criterion comment="File %windir%\system32\drivers\rdpwd.sys version is less than 5.0.2195.5880" negate="false" test_ref="oval:org.mitre.oval:tst:2815"/>
          <criterion comment="Patch Q324380 installed" negate="true" test_ref="oval:org.mitre.oval:tst:2814"/>
          <criterion comment="SP4 or later Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3073"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="RDP Enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2813"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:198" version="1" class="vulnerability">
      <metadata>
        <title>Automatic ActiveX Approval on Windows 2000 Low Memory</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0660" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0660"/>
        <description>The Authenticode capability in Microsoft Windows NT through Server 2003 does not prompt the user to download and install ActiveX controls when the system is low on memory, which could allow remote attackers execute arbitrary code without user approval.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-16T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if downloading of signed ActiveX controls are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </modified>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="File %windir%\system32\cryptui.dll version is less than 5.131.2195.6758" negate="false" test_ref="oval:org.mitre.oval:tst:2817"/>
          <criterion comment="Patch WindowsXP-KB823182-x86-ENU Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2841"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="downloading of signed ActiveX controls is enabled">
            <criteria operator="AND" comment="current user settings are being used and the downloading of signed ActiveX controls is enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="downloading of signed ActiveX controls is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2840"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and the downloading of signed ActiveX controls is enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="downloading of signed ActiveX controls is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2839"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1978" version="7" class="vulnerability">
      <metadata>
        <title>Uninitialized Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference ref_id="CVE-2007-1751" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1751" source="CVE"/>
        <description>Microsoft Internet Explorer 5.01, 6, and 7 allows remote attackers to execute arbitrary code by causing Internet Explorer to access an uninitialized or deleted object, related to prototype variables and table cells, aka "Uninitialized Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2007-06-13T08:22:59.000-04:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-06-13T15:20:00.000-04:00">DRAFT</status_change>
            <modified comment="Added Vista as an affected platform." date="2007-06-16T11:52:00.397-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-07-03T14:05:58.288-04:00">INTERIM</status_change>
            <status_change date="2007-07-18T15:57:51.867-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1978 - Updates made to criteria user correct IDs and comments." date="2011-01-07T14:47:00.112-05:00">
              <contributor organization="G2, Inc.">Jeff Cockerill</contributor>
            </modified>
            <status_change date="2011-01-07T14:50:43.692-05:00">INTERIM</status_change>
            <status_change date="2011-01-24T04:00:31.962-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1978 - Correcting incorrect references to 64-bit Itanium XP." date="2012-08-23T17:47:00.168-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-08-23T17:52:43.283-04:00">INTERIM</status_change>
            <status_change date="2012-09-10T04:00:43.775-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:54.971-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:26.305-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 5.01,SP4 on Win2k,SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="the version of Mshtml.dll is less than 5.0.3853.3000" test_ref="oval:org.mitre.oval:tst:3507"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win 2k, SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the version of Mshtml.dll is less than 6.0.2800.1595" test_ref="oval:org.mitre.oval:tst:3202"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win XP SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of Mshtml.dll is less than 6.0.2900.3132" test_ref="oval:org.mitre.oval:tst:3224"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win 2k3 SP1">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of Mshtml.dll is less than 6.0.3790.2920" test_ref="oval:org.mitre.oval:tst:3899"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win 2k3 SP2">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of Mshtml.dll is less than 6.0.3790.4064" test_ref="oval:org.mitre.oval:tst:3773"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 on Win XP SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="the version of Mshtml.dll is less than 7.0.6000.16481" test_ref="oval:org.mitre.oval:tst:3781"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 on Win 2k3 SP1 or SP2">
          <criteria operator="OR" comment="Win 2k3 SP1 or SP2">
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="the version of Mshtml.dll is less than 7.0.6000.16481" test_ref="oval:org.mitre.oval:tst:3781"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 on Win Vista">
          <extend_definition comment="Microsoft Windows Vista is installed" definition_ref="oval:org.mitre.oval:def:228"/>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="the version of Mshtml.dll is less than 7.0.6000.16481" test_ref="oval:org.mitre.oval:tst:3781"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win XP SP2 (64-bit)">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of Mshtml.dll is less than 6.0.3790.4064" test_ref="oval:org.mitre.oval:tst:3773"/>
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win XP SP1 (64-bit)">
          <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of Mshtml.dll is less than 6.0.3790.2920" test_ref="oval:org.mitre.oval:tst:3899"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 on Win XP SP2 (64-bit)">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="the version of Mshtml.dll is less than 7.0.6000.16481" test_ref="oval:org.mitre.oval:tst:3781"/>
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1973" version="7" class="vulnerability">
      <metadata>
        <title>COM Object Instantiation Memory Corruption Vulnerability (2K/XP)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1303" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1303"/>
        <description>Multiple unspecified vulnerabilities in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allow remote attackers to execute arbitrary code by instantiating certain COM objects from Wmm2fxa.dll as ActiveX controls including (1) DXImageTransform.Microsoft.MMSpecialEffect1Input, (2) DXImageTransform.Microsoft.MMSpecialEffect1Input.1, (3) DXImageTransform.Microsoft.MMSpecialEffect2Inputs, (4) DXImageTransform.Microsoft.MMSpecialEffect2Inputs.1, (5) DXImageTransform.Microsoft.MMSpecialEffectInplace1Input, and (6) DXImageTransform.Microsoft.MMSpecialEffectInplace1Input.1, which causes memory corruption during garbage collection.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:40.654-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:44.453-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:46:00.041-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:03.508-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:46:24.366-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:02:12.252-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:56.276-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:26.192-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Win2K or XP,SP1 is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2800.1555" negate="false" test_ref="oval:org.mitre.oval:tst:802"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:197" version="7" class="vulnerability">
      <metadata>
        <title>IIS ISAPI Extension Indexing Service Buffer Overflow (Code Red)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0500" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0500"/>
        <description>Buffer overflow in ISAPI extension (idq.dll) in Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier allows remote attackers to execute arbitrary commands via a long argument to Internet Data Administration (.ida) and Internet Data Query (.idq) files such as default.ida, as commonly exploited by Code Red.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2004-08-04T12:00:00.000-04:00" comment="Modifed without comment">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </modified>
            <status_change date="2004-08-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected to use a forward slash as the separator in the key." date="2007-05-07T15:59:00.817-04:00">
              <contributor organization="Secure Elements, Inc.">Glenn Strickland</contributor>
            </modified>
            <status_change date="2007-05-07T16:03:31.923-04:00">INTERIM</status_change>
            <status_change date="2007-05-23T15:05:35.420-04:00">ACCEPTED</status_change>
            <modified comment="Multiple corrections and update to POSIX compatibility for ste:2884" date="2010-11-29T16:14:00.692-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-11-29T16:14:39.568-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:38.939-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:10.160-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:02:11.628-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
          <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
          <criterion comment="File %windir%\system32\idq.dll version is less than 5.0.2195.3645" negate="false" test_ref="oval:org.mitre.oval:tst:2820"/>
          <criterion comment="Patch Q300972 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2819"/>
          <criterion comment="Patch Q301625 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3037"/>
          <criterion comment="Patch Q319733 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3095"/>
          <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
          <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
          <criterion comment="Windows 2000 Security Roll-up 1 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2990"/>
          <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3079"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="idq.dll mapping exists" negate="false" test_ref="oval:org.mitre.oval:tst:2818"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1955" version="3" class="vulnerability">
      <metadata>
        <title>Mozilla Cross-site Scripting Using .valueOf.call()</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1731" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1731"/>
        <description>Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 returns the Object class prototype instead of the global window object when (1) .valueOf.call or (2) .valueOf.apply are called without any arguments, which allows remote attackers to conduct cross-site scripting (XSS) attacks.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-07T09:05:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:39.953-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:1133" date="2007-02-26T08:08:00.208-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-26T08:09:14.353-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:1135" date="2007-02-26T08:21:00.993-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:1136" date="2007-02-26T08:24:00.848-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:1138" date="2007-02-26T08:25:00.405-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:2283" date="2007-02-26T08:29:00.407-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:2284" date="2007-02-26T08:30:00.724-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:17:09.407-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:881" date="2007-04-23T12:05:00.811-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:12:52.268-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:882" date="2007-04-23T12:05:00.939-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in obj:883" date="2007-04-23T12:05:00.804-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in obj:1385" date="2007-04-23T12:05:00.430-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:11:03.043-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1268"/>
          <criterion comment="Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1267"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Thunderbird version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1266"/>
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1265"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.12 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1264"/>
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1263"/>
        </criteria>
        <criteria operator="AND" comment="A pre-release of SeaMonkey 1.0 is installed">
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2439"/>
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2438"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1950" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft Outlook Express v6,SP1 Malformed Email Header Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Outlook Express</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0215" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0215"/>
        <description>Microsoft Outlook Express 5.5 and 6 allows attackers to cause a denial of service (application crash) via a malformed e-mail header.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-08-26T08:05:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2004-08-26T08:14:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-29T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed obj:533: changed Hive from HKEY_CLASSES_ROOT to HKEY_LOCAL_MACHINE.  Implemented by Harvey Rubinovitz." date="2007-01-22T01:12:00.977-05:00">
              <contributor organization="GFI Software">Daniel Tarnu</contributor>
            </modified>
            <status_change date="2007-01-22T01:12:58.739-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:03.348-05:00">ACCEPTED</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.788-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-10-25T16:52:38.963-04:00">INTERIM</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.053-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-11-13T12:01:03.958-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Outlook Express 6 SP1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1355"/>
          <criterion comment="the version of inetcomm.dll is less than 6.0.2800.1441" negate="false" test_ref="oval:org.mitre.oval:tst:669"/>
          <criterion comment="the patch kb823353 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:668"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="all users have the preview pane disabled" negate="true" test_ref="oval:org.mitre.oval:tst:667"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1944" version="7" class="vulnerability">
      <metadata>
        <title>ActiveX Control Memory Corruption Vulnerability (2K/XP)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2383" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2383"/>
        <description>Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remote attackers to execute arbitrary code via "unexpected data" related to "parameter validation" in the DXImageTransform.Microsoft.Light ActiveX control, which causes Internet Explorer to crash in a way that enables the code execution.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:39.465-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:42.685-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:46:05.587-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:03.054-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:43:51.250-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:02:09.235-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:33.439-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:26.104-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Win2K or XP,SP1 is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2800.1555" negate="false" test_ref="oval:org.mitre.oval:tst:802"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1943" version="2" class="vulnerability">
      <metadata>
        <title>IE .chm Directory Traversal Windows 2000 Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>HTML Help Facility</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1041" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1041"/>
        <description>Internet Explorer 5.x and 6.0 allows remote attackers to execute arbitrary programs via a modified directory traversal attack using a URL containing ".." (dot dot) sequences and a filename that ends in "::" which is treated as a .chm file even if it does not have a .chm extension.  NOTE: this bug may overlap CVE-2004-0475.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-08-04T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected obj:964. Changed registry key name from a pattern match of .* to nil." date="2007-02-12T13:46:00.470-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-12T13:47:37.482-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:08.910-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="the version of itss.dll is less than 5.2.3790.185" negate="false" test_ref="oval:org.mitre.oval:tst:1406"/>
          <criterion comment="the patch kb840315 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1405"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="HTML Help is registered" negate="true" test_ref="oval:org.mitre.oval:tst:1404"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1939" version="3" class="vulnerability">
      <metadata>
        <title>COM Object Instantiation Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0942" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0942"/>
        <description>Microsoft Internet Explorer 5.01 SP4 on Windows 2000 SP4; 6 SP1 on Windows 2000 SP4; 6 and 7 on Windows XP SP2, or Windows Server 2003 SP1 or SP2; and possibly 7 on Windows Vista does not properly "instantiate certain COM objects as ActiveX controls," which allows remote attackers to execute arbitrary code via a crafted COM object from chtskdic.dll.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-05-08T19:30:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-05-09T12:53:06-04:00">DRAFT</status_change>
            <status_change date="2007-05-31T15:26:37.822-04:00">INTERIM</status_change>
            <modified comment="Corrected version of ste:3224. Implemented by Jon Baker of the MITRE Corporation." date="2007-06-04T08:42:00.584-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <modified comment="Corrected criteria on 64 bit check" date="2007-06-07T08:42:00.584-04:00">
              <contributor organization="Secure Elements, Inc.">Jeff Ito</contributor>
            </modified>
            <status_change date="2007-06-22T08:57:42.127-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3877 - modified comments" date="2014-02-28T15:13:00.247-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-28T15:16:17.113-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:15.131-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="IE 5.01,SP4 on Win2k,SP4" operator="AND">
          <extend_definition comment="Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Internet Explorer 5.01, SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3850.1900" test_ref="oval:org.mitre.oval:tst:3859"/>
        </criteria>
        <criteria comment="IE 6 on Windows 2000" operator="AND">
          <extend_definition comment="Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1593" test_ref="oval:org.mitre.oval:tst:3454"/>
        </criteria>
        <criteria comment="IE 6 on Windows XP SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1593" test_ref="oval:org.mitre.oval:tst:3454"/>
        </criteria>
        <criteria comment="XP,SP1 (64-bit) and Server 2003, SP1 (IE6)" operator="AND">
          <criteria operator="OR" comment="Windows XP (64-bit,SP1) or Server 2003 (SP1) is installed">
            <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          </criteria>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2885" test_ref="oval:org.mitre.oval:tst:3810"/>
        </criteria>
        <criteria comment="XP,SP2 (64-bit) and Server 2003, SP2 (IE6)" operator="AND">
          <criteria operator="OR" comment="Windows XP (64-bit,SP2) or Server 2003 (SP1) is installed">
            <criteria operator="AND" comment="Windows XP (64-bit,SP2) is installed">
              <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
              <criterion comment="64-Bit version of Windows is installed" test_ref="oval:org.mitre.oval:tst:2744"/>
            </criteria>
            <extend_definition comment="Windows Server 2003, SP2 is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          </criteria>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.4026" test_ref="oval:org.mitre.oval:tst:3176"/>
        </criteria>
        <criteria comment="IE 7 on Windows XP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="the version of Ieapfltr.dll is less than 7.0.6000.16432" test_ref="oval:org.mitre.oval:tst:3877"/>
        </criteria>
        <criteria comment="Windows Server 2003 Service Pack 1 version" operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 (x86) SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of Ieapfltr.dll is less than 7.0.6000.16432" test_ref="oval:org.mitre.oval:tst:3877"/>
        </criteria>
        <criteria comment="Windows Server 2003 Service Pack 2 version" operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <criterion comment="the version of Ieapfltr.dll is less than 7.0.6000.16432" test_ref="oval:org.mitre.oval:tst:3877"/>
        </criteria>
        <criteria comment="IE 7 on Windows Vista" operator="AND">
          <extend_definition comment="Windows Vista is installed" definition_ref="oval:org.mitre.oval:def:228"/>
          <criterion comment="the version of mshtml.dll is less than 7.0.6000.20547" test_ref="oval:org.mitre.oval:tst:3334"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1927" version="3" class="vulnerability">
      <metadata>
        <title>GDI Incorrect Parameter Local Elevation of Privilege Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1215" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1215"/>
        <description>Buffer overflow in the Graphics Device Interface (GDI) in Microsoft Windows 2000 SP4; XP SP2; Server 2003 Gold, SP1, and SP2; and Vista allows local users to gain privileges via certain "color-related parameters" in crafted images.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-04-09T09:49:32">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-04-09T11:20:00.000-05:00">DRAFT</status_change>
            <status_change date="2007-04-25T19:52:21.223-04:00">INTERIM</status_change>
            <modified comment="Altered S03 section of criteria to reference proper Gdi32.dll file versions for S03,SP1 and S03,SP2." date="2007-04-26T14:38:00.383-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-05-23T15:05:34.382-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1927 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:05:14.288-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:23.569-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="gdi32.dll version is less than 5.0.2195.7133" test_ref="oval:org.mitre.oval:tst:3337"/>
        </criteria>
        <criteria operator="AND" comment="Windows XP SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="gdi32.dll version is less than 5.1.2600.3099" test_ref="oval:org.mitre.oval:tst:3215"/>
        </criteria>
        <criteria operator="AND" comment="S03-Gold">
          <extend_definition comment="Microsoft Windows Server 2003 (x86) Gold is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="gdi32.dll version is less than 5.2.3790.651" test_ref="oval:org.mitre.oval:tst:4019"/>
        </criteria>
        <criteria operator="AND" comment="S03,SP1">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="gdi32.dll version is less than 5.2.3790.2892" test_ref="oval:org.mitre.oval:tst:3548"/>
        </criteria>
        <criteria operator="AND" comment="S03,SP2">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <criterion comment="gdi32.dll version is less than 5.2.3790.4033" test_ref="oval:org.mitre.oval:tst:3612"/>
        </criteria>
        <criteria operator="AND" comment="Windows Vista">
          <extend_definition comment="Microsoft Windows Vista is installed" definition_ref="oval:org.mitre.oval:def:228"/>
          <criterion comment="the version of user32.dll is less than 6.0.6000.16438" test_ref="oval:org.mitre.oval:tst:3182"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1924" version="8" class="vulnerability">
      <metadata>
        <title>ActiveX Control Memory Corruption Vulnerability (Win2K)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2383" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2383"/>
        <description>Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remote attackers to execute arbitrary code via "unexpected data" related to "parameter validation" in the DXImageTransform.Microsoft.Light ActiveX control, which causes Internet Explorer to crash in a way that enables the code execution.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:38.543-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:40.378-04:00">ACCEPTED</status_change>
            <modified comment="Fixed ste:2614: set datatype to version.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:54:00.319-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:59:43.835-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:02.817-05:00">ACCEPTED</status_change>
            <modified comment="Fixed regex in ste:2889.  Implemented by Matthew Wojcik." date="2007-03-06T18:19:00.507-05:00">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2007-03-06T18:21:14.118-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:08.440-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:43:56.170-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:02:07.075-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:36.733-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:25.968-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3841.1900" negate="false" test_ref="oval:org.mitre.oval:tst:957"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1923" version="3" class="vulnerability">
      <metadata>
        <title>EMF Elevation of Privilege Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1212" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1212"/>
        <description>Buffer overflow in the Graphics Device Interface (GDI) in Microsoft Windows 2000 SP4; XP SP2; Server 2003 Gold, SP1, and SP2; and Vista allows local users to gain privileges via a crafted Enhanced Metafile (EMF) image format file.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-04-09T09:49:32">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-04-09T11:20:00.000-05:00">DRAFT</status_change>
            <status_change date="2007-04-25T19:52:20.881-04:00">INTERIM</status_change>
            <modified comment="Altered S03 section of criteria to reference proper Gdi32.dll file versions for S03,SP1 and S03,SP2." date="2007-04-26T14:43:00.162-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-05-23T15:05:34.096-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1923 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:04:55.276-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:23.113-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="gdi32.dll version is less than 5.0.2195.7133" test_ref="oval:org.mitre.oval:tst:3337"/>
        </criteria>
        <criteria operator="AND" comment="Windows XP SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="gdi32.dll version is less than 5.1.2600.3099" test_ref="oval:org.mitre.oval:tst:3215"/>
        </criteria>
        <criteria operator="AND" comment="S03-Gold">
          <extend_definition comment="Microsoft Windows Server 2003 (x86) Gold is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="gdi32.dll version is less than 5.2.3790.651" test_ref="oval:org.mitre.oval:tst:4019"/>
        </criteria>
        <criteria operator="AND" comment="S03,SP1">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="gdi32.dll version is less than 5.2.3790.2892" test_ref="oval:org.mitre.oval:tst:3548"/>
        </criteria>
        <criteria operator="AND" comment="S03,SP2">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <criterion comment="gdi32.dll version is less than 5.2.3790.4033" test_ref="oval:org.mitre.oval:tst:3612"/>
        </criteria>
        <criteria operator="AND" comment="Windows Vista">
          <extend_definition comment="Microsoft Windows Vista is installed" definition_ref="oval:org.mitre.oval:def:228"/>
          <criterion comment="the version of user32.dll is less than 6.0.6000.16438" test_ref="oval:org.mitre.oval:tst:3182"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1914" version="7" class="vulnerability">
      <metadata>
        <title>CSS Cross-Domain Information Disclosure Vulnerability (2K/XP)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-4089" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4089"/>
        <description>Microsoft Internet Explorer allows remote attackers to bypass cross-domain security restrictions and obtain sensitive information by using the @import directive to download files from other domains that are not valid Cascading Style Sheets (CSS) files, as demonstrated using Google Desktop, aka "CSSXSS" and "CSS Cross-Domain Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:37.921-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:39.060-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:46:00.897-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:02.643-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:44:18.296-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:02:05.302-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:41.939-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:25.879-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Win2K or XP,SP1 is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2800.1555" negate="false" test_ref="oval:org.mitre.oval:tst:802"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:19136" version="9" class="vulnerability">
      <metadata>
        <title>Cross-site scripting vulnerability in Microsoft SharePoint (CVE-2013-3180) - MS13-067</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft SharePoint Foundation 2010</product>
          <product>Microsoft SharePoint Foundation 2013</product>
          <product>Microsoft SharePoint Server 2010</product>
          <product>Microsoft SharePoint Server 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3180" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3180"/>
        <description>Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 SP1 and SP2 and 2013 allows remote attackers to inject arbitrary web script or HTML via a crafted POST request, aka "POST XSS Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-10-16T14:45:34">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-10-23T11:48:44.387-04:00">DRAFT</status_change>
            <status_change date="2013-11-11T04:01:51.214-05:00">INTERIM</status_change>
            <status_change date="2013-11-26T13:49:27.136-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:19136 - updated to check proper version as per bulletin." date="2014-01-16T10:58:00.923-05:00">
              <contributor organization="SecPod Technologies">Pooja Shetty</contributor>
            </modified>
            <status_change date="2014-01-16T10:59:41.814-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:01:12.485-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:1390 - November 2014 bulletins." date="2014-11-17T17:25:00.386-05:00">
              <contributor organization="SecPod Technologies">Kumarswamy S</contributor>
            </modified>
            <status_change date="2014-11-17T17:29:49.370-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:16.378-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:1569 - MS Bulletins - May 2015" date="2015-05-28T14:06:00.511-04:00">
              <contributor organization="SecPod Technologies">Kumarswamy S</contributor>
            </modified>
            <status_change date="2015-05-28T14:09:56.946-04:00">INTERIM</status_change>
            <status_change date="2015-06-15T04:00:11.388-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="foundation 2010/version">
          <criterion comment="Check if the version of onetutil.dll is less than 14.0.7105.5000" test_ref="oval:org.mitre.oval:tst:87199"/>
          <criteria operator="OR" comment="foundation 2010 sp1/sp2">
            <extend_definition comment="Microsoft SharePoint Foundation 2010 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:15661"/>
            <extend_definition comment="Microsoft SharePoint Foundation 2010 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:19047"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="sharepoint server 2010/version">
          <criteria operator="OR" comment="sharepoint server 2010 sp1/sp2">
            <extend_definition comment="Microsoft SharePoint Server 2010 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:15614"/>
            <extend_definition comment="Microsoft SharePoint Server 2010 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:18921"/>
          </criteria>
          <criteria operator="OR" comment="either files versions">
            <criterion comment="Check if the version of microsoft.office.server.native.dll is less than 14.0.7005.1000" test_ref="oval:org.mitre.oval:tst:87074"/>
            <criterion comment="Check if the version of WdsrvWorker.dll is less than 14.0.6112.5000" test_ref="oval:org.mitre.oval:tst:87135"/>
            <criterion comment="Check if the version of xlsrv.dll is less than 14.0.7104.5000 (sharepoint server)" test_ref="oval:org.mitre.oval:tst:86965"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="foundation 2013/version">
          <criterion comment="Check if the version of Microsoft.office.server.native.dll is less than 15.0.4535.1000" test_ref="oval:org.mitre.oval:tst:87023"/>
          <extend_definition comment="Microsoft SharePoint Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:16325"/>
        </criteria>
        <criteria operator="AND" comment="sharepoint foundation 2013/version">
          <extend_definition comment="Microsoft SharePoint Foundation 2013 is installed" definition_ref="oval:org.mitre.oval:def:19090"/>
          <criterion comment="Check if the version of Onfda.dll is less than 15.0.4535.1000" test_ref="oval:org.mitre.oval:tst:86497"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:19090" version="3" class="inventory">
      <metadata>
        <title>Microsoft SharePoint Foundation 2013 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft SharePoint Foundation 2013</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:sharepoint_foundation:2013"/>
        <description>Microsoft SharePoint Foundation 2013 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2013-10-16T13:16:37">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-10-23T11:48:15.530-04:00">DRAFT</status_change>
            <status_change date="2013-11-11T04:01:44.863-05:00">INTERIM</status_change>
            <status_change date="2013-11-26T13:49:25.849-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Microsoft SharePoint Foundation 2013 is installed" test_ref="oval:org.mitre.oval:tst:87180"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:19047" version="3" class="inventory">
      <metadata>
        <title>Microsoft SharePoint Foundation 2010 Service Pack 2 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft SharePoint Foundation 2010</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:sharepoint_foundation:2010:sp2"/>
        <description>Microsoft SharePoint Foundation 2010 Service Pack 2 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2013-10-16T14:45:34">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-10-23T11:48:10.996-04:00">DRAFT</status_change>
            <status_change date="2013-11-11T04:01:34.923-05:00">INTERIM</status_change>
            <status_change date="2013-11-26T13:49:24.234-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft SharePoint Foundation 2010 is installed" definition_ref="oval:org.mitre.oval:def:12224"/>
        <criterion comment="Check if Microsoft SharePoint Foundation 2010 SP2 is installed" test_ref="oval:org.mitre.oval:tst:87020"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16325" version="3" class="inventory">
      <metadata>
        <title>Microsoft SharePoint Server 2013 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft SharePoint Server 2013</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:sharepoint_server:2013"/>
        <description>Microsoft SharePoint Server 2013 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2013-04-12T10:24:08">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-04-15T21:05:34.844-04:00">DRAFT</status_change>
            <status_change date="2013-05-06T04:02:05.965-04:00">INTERIM</status_change>
            <status_change date="2013-05-27T04:00:08.177-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if SharePoint Server 2013 is installed" test_ref="oval:org.mitre.oval:tst:80504"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1911" version="8" class="vulnerability">
      <metadata>
        <title>MHT Memory Corruption Vulnerability (Win2K)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2385" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2385"/>
        <description>Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows user-assisted remote attackers to execute arbitrary code via a crafted web page that triggers memory corruption when it is saved as a multipart HTML (.mht) file.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:37.622-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:38.616-04:00">ACCEPTED</status_change>
            <modified comment="Fixed ste:2614: set datatype to version.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:54:00.319-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:59:44.200-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:02.489-05:00">ACCEPTED</status_change>
            <modified comment="Fixed regex in ste:2889.  Implemented by Matthew Wojcik." date="2007-03-06T18:19:00.507-05:00">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2007-03-06T18:21:09.872-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:08.249-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:44:16.711-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:02:04.575-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:41.769-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:25.793-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3841.1900" negate="false" test_ref="oval:org.mitre.oval:tst:957"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:19100" version="3" class="vulnerability">
      <metadata>
        <title>Denial of service vulnerability in Microsoft SharePoint (CVE-2013-3849) - MS13-067</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft SharePoint Server 2010</product>
          <product>Microsoft Office Web Apps</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3849" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3849"/>
        <description>Microsoft Word Automation Services in SharePoint Server 2010 SP1, Word Web App 2010 SP1 in Office Web Apps 2010, Word 2003 SP3, Word 2007 SP3, Word 2010 SP1, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3847, CVE-2013-3848, and CVE-2013-3858.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-10-16T14:45:34">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-10-23T11:48:29.586-04:00">DRAFT</status_change>
            <status_change date="2013-11-11T04:01:48.195-05:00">INTERIM</status_change>
            <status_change date="2013-11-26T13:49:26.489-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="sharepoint server 2010/version">
          <extend_definition comment="Microsoft SharePoint Server 2010 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:15614"/>
          <criterion comment="Check if the version of WdsrvWorker.dll is less than 14.0.6112.5000" test_ref="oval:org.mitre.oval:tst:87135"/>
        </criteria>
        <criteria operator="AND" comment="web apps/version">
          <extend_definition comment="Microsoft Office Web Apps 2010 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:15860"/>
          <criterion comment="Check if the version of msoserver.dll is less than 14.0.7106.5000" test_ref="oval:org.mitre.oval:tst:87179"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:191" version="5" class="vulnerability">
      <metadata>
        <title>IIS Web Server File Request Parsing</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2000-0886" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0886"/>
        <description>IIS 5.0 allows remote attackers to execute arbitrary commands via a malformed request for an executable file whose name is appended with operating system commands, aka the "Web Server File Request Parsing" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified comment="Updated comment to include Vista and Server 2008" date="2009-05-07T10:32:00.713-04:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2009-05-07T10:34:00.826-04:00">INTERIM</status_change>
            <status_change date="2009-05-25T04:01:12.987-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:08.587-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:02:03.628-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Software section">
        <criterion comment="IIS major version equals 5" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS minor version equals 0" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="File %windir%\system32\inetsrv\w3svc.dll version is less than 5.0.2195.2784" test_ref="oval:org.mitre.oval:tst:2828"/>
        <criterion negate="true" comment="Patch Q277873 Installed" test_ref="oval:org.mitre.oval:tst:3021"/>
        <criterion negate="true" comment="Patch Q293826 Installed" test_ref="oval:org.mitre.oval:tst:3020"/>
        <criterion negate="true" comment="Patch Q301625 Installed" test_ref="oval:org.mitre.oval:tst:3037"/>
        <criterion negate="true" comment="Patch Q319733 Installed" test_ref="oval:org.mitre.oval:tst:3095"/>
        <criterion negate="true" comment="Patch Q327696 Installed" test_ref="oval:org.mitre.oval:tst:3094"/>
        <criterion negate="true" comment="Patch Q811114 Installed" test_ref="oval:org.mitre.oval:tst:3093"/>
        <criterion negate="true" comment="Win2K/XP/2003/Vista/2008 Service Pack 2 is installed" test_ref="oval:org.mitre.oval:tst:3019"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1904" version="6" class="vulnerability">
      <metadata>
        <title>SMB Driver Elevation of Privilege Vulnerability (Win2K)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2373" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2373"/>
        <description>The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows local users to execute arbitrary code by calling the MrxSmbCscIoctlOpenForCopyChunk function with the METHOD_NEITHER method flag and an arbitrary address, possibly for kernel memory, aka the "SMB Driver Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:36.973-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:37.356-04:00">ACCEPTED</status_change>
            <modified comment="Fixed regex in ste:2889.  Implemented by Matthew Wojcik." date="2007-03-06T18:19:00.507-05:00">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2007-03-06T18:21:07.779-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:08.092-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1904 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:05:22.567-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:02:02.521-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="the version of mrxsmb.sys is less than 5.0.2195.7097" test_ref="oval:org.mitre.oval:tst:685"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1902" version="7" class="vulnerability">
      <metadata>
        <title>Language Pack Installation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference ref_id="CVE-2007-3027" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3027" source="CVE"/>
        <description>Race condition in Microsoft Internet Explorer 5.01, 6, and 7 allows remote attackers to execute arbitrary code by causing Internet Explorer to install multiple language packs in a way that triggers memory corruption, aka "Language Pack Installation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2007-06-13T08:22:59.000-04:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-06-13T15:20:00.000-04:00">DRAFT</status_change>
            <modified comment="Removed IE7 tests for Vista and 64-bit installations." date="2007-06-15T13:46:00.059-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-07-03T14:05:56.570-04:00">INTERIM</status_change>
            <status_change date="2007-07-18T15:57:50.818-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1902 - Updates made to criteria user correct IDs and comments." date="2011-01-07T14:47:00.590-05:00">
              <contributor organization="G2, Inc.">Jeff Cockerill</contributor>
            </modified>
            <status_change date="2011-01-07T14:52:06.930-05:00">INTERIM</status_change>
            <status_change date="2011-01-24T04:00:31.392-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1902 - Correcting incorrect references to 64-bit Itanium XP." date="2012-08-23T17:47:00.168-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-08-23T17:52:49.174-04:00">INTERIM</status_change>
            <status_change date="2012-09-10T04:00:43.188-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:40.175-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:25.630-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 5.01,SP4 on Win2k,SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="the version of Mshtml.dll is less than 5.0.3853.3000" test_ref="oval:org.mitre.oval:tst:3507"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win 2k, SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the version of Mshtml.dll is less than 6.0.2800.1595" test_ref="oval:org.mitre.oval:tst:3202"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win XP SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of Mshtml.dll is less than 6.0.2900.3132" test_ref="oval:org.mitre.oval:tst:3224"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win 2k3 SP1">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of Mshtml.dll is less than 6.0.3790.2920" test_ref="oval:org.mitre.oval:tst:3899"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win 2k3 SP2">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of Mshtml.dll is less than 6.0.3790.4064" test_ref="oval:org.mitre.oval:tst:3773"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 on Win XP SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="the version of Mshtml.dll is less than 7.0.6000.16481" test_ref="oval:org.mitre.oval:tst:3781"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 on Win 2k3 SP1 or SP2">
          <criteria operator="OR" comment="Win 2k3 SP1 or SP2">
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="the version of Mshtml.dll is less than 7.0.6000.16481" test_ref="oval:org.mitre.oval:tst:3781"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win XP SP2 (64-bit)">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of Mshtml.dll is less than 6.0.3790.4064" test_ref="oval:org.mitre.oval:tst:3773"/>
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win XP SP1 (64-bit)">
          <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of Mshtml.dll is less than 6.0.3790.2920" test_ref="oval:org.mitre.oval:tst:3899"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1901" version="3" class="vulnerability">
      <metadata>
        <title>Mozilla Crashes with Evidence of Memory Corruption (CVE-2006-1724)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1724" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1724"/>
        <description>Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via attack vectors related to DHTML.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-07T09:05:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:36.624-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:1133" date="2007-02-26T08:08:00.208-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-26T08:09:16.134-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:1135" date="2007-02-26T08:21:00.993-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:1136" date="2007-02-26T08:24:00.848-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:1138" date="2007-02-26T08:25:00.405-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:17:07.625-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:881" date="2007-04-23T12:05:00.811-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:12:54.286-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:882" date="2007-04-23T12:05:00.939-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in obj:883" date="2007-04-23T12:05:00.804-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:11:01.149-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1268"/>
          <criterion comment="Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1267"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Thunderbird version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1266"/>
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1265"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.12 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1264"/>
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1263"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:190" version="7" class="vulnerability">
      <metadata>
        <title>ActiveX Certificate Enrollment Unauthorized Remote Certificate Deletion</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Certificate Enrollment Control</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0699" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0699"/>
        <description>Unknown vulnerability in the Certificate Enrollment ActiveX Control in Microsoft Windows 98, Windows 98 Second Edition, Windows Millennium, Windows NT 4.0, Windows 2000, and Windows XP allow remote attackers to delete digital certificates on a user's system via HTML.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-03-07T12:00:00.000-04:00" comment="modified wrt-222 - changed pattern match">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-03-09T07:55:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-29T07:59:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Multiple corrections and update to POSIX compatibility for ste:2878" date="2010-11-29T16:13:00.904-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-11-29T16:14:04.658-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:38.221-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:08.911-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:02:02.180-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="the version of xenroll.dll is less than 5.131.3659.0" negate="false" test_ref="oval:org.mitre.oval:tst:2831"/>
          <criterion comment="Patch Q323172 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2830"/>
          <criterion comment="SP4 or later Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3073"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="ActiveX Enabled">
            <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
            <criterion comment="ActiveX Enabled In At Least One Zone" negate="false" test_ref="oval:org.mitre.oval:tst:2829"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:19" version="8" class="vulnerability">
      <metadata>
        <title>IE Cross-Site Scripting</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0189" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0189"/>
        <description>Cross-site scripting vulnerability in Internet Explorer 6.0 allows remote attackers to execute scripts in the Local Computer zone via a URL that exploits a local HTML resource file, aka the "Cross-Site Scripting in Local HTML Resource" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-27T05:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Changed IE registry test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-07-03T12:56:00.000-04:00" comment="Added negate=true attribute to criteria sub-block to fix conversion error from OVAL 4.2 to OVAL 5.0">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-07-03T12:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:04.771-04:00">ACCEPTED</status_change>
            <modified comment="Fixed regex in ste:2889.  Implemented by Matthew Wojcik." date="2007-03-06T18:19:00.507-05:00">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2007-03-06T18:21:09.603-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:07.349-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:36.273-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:02:01.640-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:42.879-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:25.465-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the version of mshtml.dll is less than 6.0.2716.2200" negate="false" test_ref="oval:org.mitre.oval:tst:3086"/>
        <criterion comment="the patch q321232 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3119"/>
        <criterion comment="the patch q323759 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3118"/>
        <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
        <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
        <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed" negate="true">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18988" version="3" class="vulnerability">
      <metadata>
        <title>Denial of service vulnerability in Microsoft SharePoint (CVE-2013-3847) - MS13-067</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft SharePoint Server 2010</product>
          <product>Microsoft Office Web Apps</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3847" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3847"/>
        <description>Microsoft Word Automation Services in SharePoint Server 2010 SP1, Word Web App 2010 SP1 in Office Web Apps 2010, Word 2003 SP3, Word 2007 SP3, Word 2010 SP1, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3848, CVE-2013-3849, and CVE-2013-3858.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-10-16T14:45:34">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-10-23T11:48:26.744-04:00">DRAFT</status_change>
            <status_change date="2013-11-11T04:01:17.125-05:00">INTERIM</status_change>
            <status_change date="2013-11-26T13:49:20.571-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="sharepoint server 2010/version">
          <extend_definition comment="Microsoft SharePoint Server 2010 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:15614"/>
          <criterion comment="Check if the version of WdsrvWorker.dll is less than 14.0.6112.5000" test_ref="oval:org.mitre.oval:tst:87135"/>
        </criteria>
        <criteria operator="AND" comment="web apps/version">
          <extend_definition comment="Microsoft Office Web Apps 2010 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:15860"/>
          <criterion comment="Check if the version of msoserver.dll is less than 14.0.7106.5000" test_ref="oval:org.mitre.oval:tst:87179"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1895" version="3" class="vulnerability">
      <metadata>
        <title>Windows Security Channel Remote Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2218" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2218"/>
        <description>Unspecified vulnerability in the Windows Schannel Security Package for Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2, allows remote servers to execute arbitrary code or cause a denial of service via crafted digital signatures that are processed during an SSL handshake.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-06-12T03:29:54.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-06-12T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-06-29T09:42:00.233-04:00">INTERIM</status_change>
            <status_change date="2007-07-16T09:55:11.617-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1895 - Correcting incorrect references to 64-bit Itanium XP." date="2012-08-23T17:47:00.168-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-08-23T17:52:46.657-04:00">INTERIM</status_change>
            <status_change date="2012-09-10T04:00:42.686-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win2K,SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of schannel.dll is less than 5.1.2195.7136" test_ref="oval:org.mitre.oval:tst:3923"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of schannel.dll is less than 5.1.2600.3126" test_ref="oval:org.mitre.oval:tst:3933"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP1 (64-bit)">
          <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="the version of schannel.dll is less than 5.2.3790.2924" test_ref="oval:org.mitre.oval:tst:4076"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP2 (64-bit)">
          <criterion comment="the version of schannel.dll is less than 5.2.3790.4068" test_ref="oval:org.mitre.oval:tst:3754"/>
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
        </criteria>
        <criteria operator="AND" comment="S03,SP1">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of schannel.dll is less than 5.2.3790.2924" test_ref="oval:org.mitre.oval:tst:4076"/>
        </criteria>
        <criteria operator="AND" comment="S03,SP2">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <criterion comment="the version of schannel.dll is less than 5.2.3790.4068" test_ref="oval:org.mitre.oval:tst:3754"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18942" version="3" class="vulnerability">
      <metadata>
        <title>Word memory corruption vulnerability in Microsoft SharePoint (CVE-2013-3857) - MS13-067</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft SharePoint Server 2010</product>
          <product>Microsoft Office Web Apps</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3857" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3857"/>
        <description>Microsoft Word Automation Services in SharePoint Server 2010 SP1 and SP2, Word Web App 2010 SP1 and SP2 in Office Web Apps 2010, Word 2003 SP3, Word 2007 SP3, Word 2010 SP1 and SP2, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-10-16T14:45:34">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-10-23T11:48:36.867-04:00">DRAFT</status_change>
            <status_change date="2013-11-11T04:01:04.763-05:00">INTERIM</status_change>
            <status_change date="2013-11-26T13:49:18.228-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="sharepoint server 2010/version">
          <criteria operator="OR" comment="sharepoint server 2010 sp1/sp2">
            <extend_definition comment="Microsoft SharePoint Server 2010 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:15614"/>
            <extend_definition comment="Microsoft SharePoint Server 2010 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:18921"/>
          </criteria>
          <criterion comment="Check if the version of WdsrvWorker.dll is less than 14.0.6112.5000" test_ref="oval:org.mitre.oval:tst:87135"/>
        </criteria>
        <criteria operator="AND" comment="web apps/version">
          <criteria operator="OR" comment="office web apps sp1/sp2">
            <extend_definition comment="Microsoft Office Web Apps 2010 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:15860"/>
            <extend_definition comment="Microsoft Office Web Apps 2010 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:19186"/>
          </criteria>
          <criterion comment="Check if the version of msoserver.dll is less than 14.0.7106.5000" test_ref="oval:org.mitre.oval:tst:87179"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:19186" version="6" class="inventory">
      <metadata>
        <title>Microsoft Office Web Apps 2010 Service Pack 2 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Office Web Apps 2010</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:office_web_apps:2010:sp2"/>
        <description>Microsoft Office Web Apps 2010 Service Pack 2 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2013-10-16T14:45:34">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-10-23T11:48:16.599-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:26572 - '\' precedding '_' removed in object regex;un-deprecated registry state" date="2013-11-08T09:48:00.143-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-11-26T13:49:28.297-05:00">INTERIM</status_change>
            <status_change date="2013-12-16T04:01:31.088-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:26572 - In some &quot;pattern match&quot; strings added &quot;\&quot; before &quot;.&quot; to clarify if &quot;point&quot; or &quot;any symbol&quot; needed." date="2014-07-28T18:11:00.493-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-28T18:14:47.701-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:07.926-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Office Web Apps 2010 is installed" definition_ref="oval:org.mitre.oval:def:15787"/>
        <criterion comment="Check if Microsoft Office Web Apps 2010 SP2 is installed" test_ref="oval:org.mitre.oval:tst:86576"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18921" version="5" class="inventory">
      <metadata>
        <title>Microsoft SharePoint Server 2010 Service Pack 2 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft SharePoint Server 2010</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:sharepoint_server:2010:sp2"/>
        <description>Microsoft SharePoint Server 2010 SP2 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2013-10-16T14:45:34">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-10-23T11:48:12.179-04:00">DRAFT</status_change>
            <status_change date="2013-11-11T04:00:58.881-05:00">INTERIM</status_change>
            <status_change date="2013-11-26T13:49:16.818-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:23979 - ms14-001, new registry tst to detect SP's properly, def:18921 15614 updated to check display version" date="2014-01-21T16:50:00.071-05:00">
              <contributor organization="SecPod Technologies">Pooja Shetty</contributor>
            </modified>
            <status_change date="2014-01-21T17:03:44.673-05:00">INTERIM</status_change>
            <status_change date="2014-02-10T04:00:10.747-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Office SharePoint Server 2010 is installed." definition_ref="oval:org.mitre.oval:def:12880"/>
        <criterion comment="Check if Microsoft SharePoint 2010 SP2 is installed" test_ref="oval:org.mitre.oval:tst:86608"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1890" class="vulnerability" version="2">
      <metadata>
        <title>MIME Decoding Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Exchange Server</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0213" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0213"/>
        <description>Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 does not properly decode certain MIME encoded e-mails, which allows remote attackers to execute arbitrary code via a crafted base64-encoded MIME e-mail message.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-05-09T10:04:48">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-05-09T12:53:06-04:00">DRAFT</status_change>
            <status_change date="2007-05-31T15:26:37.157-04:00">INTERIM</status_change>
            <status_change date="2007-06-15T11:07:36.641-04:00">ACCEPTED</status_change>
            <modified comment="References registry value for Common Files directory due to multilingual support" date="2008-04-14T11:07:00.679-04:00">
              <contributor organization="GFI Software">Clifford Farrugia</contributor>
            </modified>
            <status_change date="2008-04-14T12:26:45.478-04:00">INTERIM</status_change>
            <status_change date="2008-05-05T04:00:14.460-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Microsoft Exchange 2000 Server Service Pack 3" operator="AND">
          <extend_definition comment="Microsoft Exchange 2000 Server Service Pack 3 is installed" definition_ref="oval:org.mitre.oval:def:1858"/>
          <criterion comment="the version of Cdoex.dll is less than 6.0.6619.12" test_ref="oval:org.mitre.oval:tst:3975"/>
        </criteria>
        <criteria comment="Microsoft Exchange Server 2003 Service Pack 1" operator="AND">
          <extend_definition comment="Microsoft Exchange Server 2003 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:1672"/>
          <criterion comment="the version of Cdoex.dll is less than 6.5.7235.2" test_ref="oval:org.mitre.oval:tst:3925"/>
        </criteria>
        <criteria comment="Microsoft Exchange Server 2003 Service Pack 2" operator="AND">
          <extend_definition comment="Microsoft Exchange Server 2003 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:1869"/>
          <criterion comment="the version of Cdoex.dll is less than 6.5.7652.24" test_ref="oval:org.mitre.oval:tst:3618"/>
        </criteria>
        <criteria comment="Microsoft Exchange Server 2007" operator="AND">
          <extend_definition comment="Microsoft Exchange Server 2007 is installed" definition_ref="oval:org.mitre.oval:def:1641"/>
          <criterion comment="the version of Cdoex.dll is less than 8.0.709.0" test_ref="oval:org.mitre.oval:tst:4122"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:189" version="6" class="vulnerability">
      <metadata>
        <title>Network Share Provider Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>SMB (Server Message Block)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0724" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0724"/>
        <description>Buffer overflow in SMB (Server Message Block) protocol in Microsoft Windows NT, Windows 2000, and Windows XP allows attackers to cause a denial of service (crash) via a SMB_COM_TRANSACTION packet with a request for the (1) NetShareEnum, (2) NetServerEnum2, or (3) NetServerEnum3, aka "Unchecked Buffer in Network Share Provider Can Lead to Denial of Service".</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <modified date="2005-03-07T12:00:00.000-04:00" comment="modified wrt-222 - changed pattern match">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-03-09T07:55:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-29T07:59:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Multiple corrections and update to POSIX compatibility for ste:2878" date="2010-11-29T16:13:00.904-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-11-29T16:14:04.353-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:37.891-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:00.893-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:02:00.701-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="the version of xactsrv.dll is less than 5.0.2195.5971" negate="false" test_ref="oval:org.mitre.oval:tst:2834"/>
          <criterion comment="Patch Q326830 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2833"/>
          <criterion comment="SP4 or later Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3073"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Lanman enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2832"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1887" version="3" class="vulnerability">
      <metadata>
        <title>Mozilla Cross-site Scripting through window.controllers</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1732" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1732"/>
        <description>Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to bypass same-origin protections and conduct cross-site scripting (XSS) attacks via unspecified vectors involving the window.controllers array.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-07T09:05:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:36.188-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:1133" date="2007-02-26T08:08:00.208-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-26T08:09:16.824-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:1135" date="2007-02-26T08:21:00.993-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:1136" date="2007-02-26T08:24:00.848-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:1138" date="2007-02-26T08:25:00.405-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:2283" date="2007-02-26T08:29:00.407-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:2284" date="2007-02-26T08:30:00.724-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:17:07.092-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:881" date="2007-04-23T12:05:00.811-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:12:55.064-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:882" date="2007-04-23T12:05:00.939-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in obj:883" date="2007-04-23T12:05:00.804-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in obj:1385" date="2007-04-23T12:05:00.430-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:11:00.552-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1268"/>
          <criterion comment="Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1267"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Thunderbird version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1266"/>
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1265"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.12 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1264"/>
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1263"/>
        </criteria>
        <criteria operator="AND" comment="A pre-release of SeaMonkey 1.0 is installed">
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2439"/>
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2438"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1885" version="3" class="vulnerability">
      <metadata>
        <title>Arbitrary File Rewrite Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2221" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2221"/>
        <description>Unspecified vulnerability in the mdsauth.dll COM object in Microsoft Windows Media Server in the Microsoft Internet Explorer 5.01 SP4 on Windows 2000 SP4; 6 SP1 on Windows 2000 SP4; 6 and 7 on Windows XP SP2, or Windows Server 2003 SP1 or SP2; or 7 on Windows Vista allows remote attackers to overwrite arbitrary files via unspecified vectors, aka the "Arbitrary File Rewrite Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2007-05-08T19:30:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-05-09T12:53:06-04:00">DRAFT</status_change>
            <status_change date="2007-05-31T15:26:36.708-04:00">INTERIM</status_change>
            <modified comment="Corrected version of ste:3224. Implemented by Jon Baker of the MITRE Corporation." date="2007-06-04T08:42:00.584-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <modified comment="Corrected criteria on 64 bit check" date="2007-06-07T08:42:00.584-04:00">
              <contributor organization="Secure Elements, Inc.">Jeff Ito</contributor>
            </modified>
            <status_change date="2007-06-22T08:57:41.647-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3877 - modified comments" date="2014-02-28T15:13:00.247-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-28T15:16:17.221-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:14.801-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="IE 5.01,SP4 on Win2k,SP4" operator="AND">
          <extend_definition comment="Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Internet Explorer 5.01, SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3850.1900" test_ref="oval:org.mitre.oval:tst:3859"/>
        </criteria>
        <criteria comment="IE 6 on Windows 2000" operator="AND">
          <extend_definition comment="Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1593" test_ref="oval:org.mitre.oval:tst:3454"/>
        </criteria>
        <criteria comment="IE 6 on Windows XP SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1593" test_ref="oval:org.mitre.oval:tst:3454"/>
        </criteria>
        <criteria comment="XP,SP1 (64-bit) and Server 2003, SP1 (IE6)" operator="AND">
          <criteria operator="OR" comment="Windows XP (64-bit,SP1) or Server 2003 (SP1) is installed">
            <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          </criteria>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2885" test_ref="oval:org.mitre.oval:tst:3810"/>
        </criteria>
        <criteria comment="XP,SP2 (64-bit) and Server 2003, SP2 (IE6)" operator="AND">
          <criteria operator="OR" comment="Windows XP (64-bit,SP2) or Server 2003 (SP1) is installed">
            <criteria operator="AND" comment="Windows XP (64-bit,SP2) is installed">
              <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
              <criterion comment="64-Bit version of Windows is installed" test_ref="oval:org.mitre.oval:tst:2744"/>
            </criteria>
            <extend_definition comment="Windows Server 2003, SP2 is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          </criteria>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.4026" test_ref="oval:org.mitre.oval:tst:3176"/>
        </criteria>
        <criteria comment="IE 7 on Windows XP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="the version of Ieapfltr.dll is less than 7.0.6000.16432" test_ref="oval:org.mitre.oval:tst:3877"/>
        </criteria>
        <criteria comment="Windows Server 2003 Service Pack 1 version" operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 (x86) SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of Ieapfltr.dll is less than 7.0.6000.16432" test_ref="oval:org.mitre.oval:tst:3877"/>
        </criteria>
        <criteria comment="Windows Server 2003 Service Pack 2 version" operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <criterion comment="the version of Ieapfltr.dll is less than 7.0.6000.16432" test_ref="oval:org.mitre.oval:tst:3877"/>
        </criteria>
        <criteria comment="IE 7 on Windows Vista" operator="AND">
          <extend_definition comment="Windows Vista is installed" definition_ref="oval:org.mitre.oval:def:228"/>
          <criterion comment="the version of mshtml.dll is less than 7.0.6000.20547" test_ref="oval:org.mitre.oval:tst:3334"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1881" version="7" class="vulnerability">
      <metadata>
        <title>Flash Address Bar Spoofing Vulnerability (2K/XP)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1626" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1626"/>
        <description>Internet Explorer 6 for Windows XP SP2 and earlier allows remote attackers to spoof the address bar and possibly conduct phishing attacks by re-opening the window to a malicious Shockwave Flash application, then changing the window location back to a trusted URL while the Flash application is still loading.  NOTE: this is a different vulnerability than CVE-2006-1192.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:36.024-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:36.435-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:46:04.695-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:02.316-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:46:14.438-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:01:59.710-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:54.090-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:24.856-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Win2K or XP,SP1 is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2800.1555" negate="false" test_ref="oval:org.mitre.oval:tst:802"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18801" version="3" class="vulnerability">
      <metadata>
        <title>Memory corruption vulnerability in Microsoft SharePoint (CVE-2013-3858) - MS13-067</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Office Web Apps</product>
          <product>Microsoft SharePoint Server 2010</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3858" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3858"/>
        <description>Microsoft Word Automation Services in SharePoint Server 2010 SP1, Word Web App 2010 SP1 in Office Web Apps 2010, Word 2003 SP3, Word 2007 SP3, Word 2010 SP1, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3847, CVE-2013-3848, and CVE-2013-3849.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-10-16T14:45:34">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-10-23T11:48:19.228-04:00">DRAFT</status_change>
            <status_change date="2013-11-11T04:00:36.426-05:00">INTERIM</status_change>
            <status_change date="2013-11-26T13:49:11.638-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="sharepoint server 2010/version">
          <extend_definition comment="Microsoft SharePoint Server 2010 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:15614"/>
          <criterion comment="Check if the version of WdsrvWorker.dll is less than 14.0.6112.5000" test_ref="oval:org.mitre.oval:tst:87135"/>
        </criteria>
        <criteria operator="AND" comment="web apps/version">
          <extend_definition comment="Microsoft Office Web Apps 2010 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:15860"/>
          <criterion comment="Check if the version of msoserver.dll is less than 14.0.7106.5000" test_ref="oval:org.mitre.oval:tst:87179"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18800" version="3" class="vulnerability">
      <metadata>
        <title>Denial of service vulnerability in Microsoft SharePoint (CVE-2013-3848) - MS13-067</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft SharePoint Server 2010</product>
          <product>Microsoft Office Web Apps</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3848" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3848"/>
        <description>Microsoft Word Automation Services in SharePoint Server 2010 SP1, Word Web App 2010 SP1 in Office Web Apps 2010, Word 2003 SP3, Word 2007 SP3, Word 2010 SP1, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3847, CVE-2013-3849, and CVE-2013-3858.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-10-16T14:45:34">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-10-23T11:48:39.934-04:00">DRAFT</status_change>
            <status_change date="2013-11-11T04:00:35.846-05:00">INTERIM</status_change>
            <status_change date="2013-11-26T13:49:11.524-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="sharepoint server 2010/version">
          <extend_definition comment="Microsoft SharePoint Server 2010 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:15614"/>
          <criterion comment="Check if the version of WdsrvWorker.dll is less than 14.0.6112.5000" test_ref="oval:org.mitre.oval:tst:87135"/>
        </criteria>
        <criteria operator="AND" comment="web apps/version">
          <extend_definition comment="Microsoft Office Web Apps 2010 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:15860"/>
          <criterion comment="Check if the version of msoserver.dll is less than 14.0.7106.5000" test_ref="oval:org.mitre.oval:tst:87179"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15860" version="7" class="inventory">
      <metadata>
        <title>Microsoft Office Web Apps 2010 Service Pack 1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Office Web Apps 2010</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:office_web_apps:2010:sp1"/>
        <description>Microsoft Office Web Apps 2010 Service Pack 1 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2012-10-17T09:07:03">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-10-19T16:11:26.152-04:00">DRAFT</status_change>
            <status_change date="2012-11-05T04:00:23.370-05:00">INTERIM</status_change>
            <status_change date="2012-11-26T04:00:14.164-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:24131 - Symbol \ (backslash) is not needed because symbol _ (underscore) isn't a metacharacter." date="2013-08-29T09:21:00.244-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-29T09:22:52.391-04:00">INTERIM</status_change>
            <status_change date="2013-09-16T04:00:21.578-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:24131 - In some &quot;pattern match&quot; strings added &quot;\&quot; before &quot;.&quot; to clarify if &quot;point&quot; or &quot;any symbol&quot; needed." date="2014-07-28T18:11:00.493-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-28T18:14:45.693-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:26.929-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Microsoft Office Web Apps SP1 is installed" test_ref="oval:org.mitre.oval:tst:80139"/>
        <extend_definition comment="Microsoft Office Web Apps 2010 is installed" definition_ref="oval:org.mitre.oval:def:15787"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15787" version="3" class="inventory">
      <metadata>
        <title>Microsoft Office Web Apps 2010 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Office Web Apps 2010</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:office_web_apps:2010"/>
        <description>Microsoft Office Web Apps 2010 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2012-10-17T14:16:01">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-10-19T16:11:25.935-04:00">DRAFT</status_change>
            <status_change date="2012-11-05T04:00:19.815-05:00">INTERIM</status_change>
            <status_change date="2012-11-26T04:00:13.143-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Microsoft Web Apps is installed" test_ref="oval:org.mitre.oval:tst:80134"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15614" version="7" class="inventory">
      <metadata>
        <title>Microsoft SharePoint Server 2010 Service Pack 1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft SharePoint Server 2010</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:sharepoint_server:2010:sp1"/>
        <description>Microsoft SharePoint Server 2010 SP1 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2012-07-16T12:35:55">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-07-19T12:32:13.329-04:00">DRAFT</status_change>
            <status_change date="2012-08-06T04:00:12.930-04:00">INTERIM</status_change>
            <status_change date="2012-08-27T04:00:29.799-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:24062 - corrected regex (symbol '\' not needed before symbol '_')" date="2013-09-06T14:20:00.865-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-09-06T14:21:25.926-04:00">INTERIM</status_change>
            <status_change date="2013-09-23T04:00:08.343-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:19908 - ms14-001, new registry tst to detect SP's properly, def:18921 15614 updated to check display version" date="2014-01-21T16:50:00.071-05:00">
              <contributor organization="SecPod Technologies">Pooja Shetty</contributor>
            </modified>
            <status_change date="2014-01-21T17:03:44.381-05:00">INTERIM</status_change>
            <status_change date="2014-02-10T04:00:06.288-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Office SharePoint Server 2010 is installed." definition_ref="oval:org.mitre.oval:def:12880"/>
        <criterion comment="Check if Microsoft SharePoint Server 2010 Service Pack 1 is installed" test_ref="oval:org.mitre.oval:tst:80093"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1873" version="3" class="vulnerability">
      <metadata>
        <title>.NET JIT Compiler Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft .NET Framework</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0043" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0043"/>
        <description>The Just In Time (JIT) Compiler service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows user-assisted remote attackers to execute arbitrary code via unspecified vectors involving an "unchecked buffer," probably a buffer overflow, aka ".NET JIT Compiler Vulnerability".</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-11T18:34:24">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-07-16T09:52:05.574-04:00">DRAFT</status_change>
            <modified comment="Removed some criterion to reflect the affected technology listed in the Microsoft bulletin" date="2007-07-16T13:39:00.107-04:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="Updated tst:3325 to use new obj:1808 to identify the .net 1.1 version of System.web.dll" date="2007-07-18T13:18:00.196-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <modified comment="Corrected obj:263 to use variable that constructs the path to the .net 1.1 directory." date="2007-07-18T13:42:00.929-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <modified comment="Added vista to the list of affected platforms" date="2007-07-19T10:50:00.658-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-08-03T16:53:35.328-04:00">INTERIM</status_change>
            <status_change date="2007-08-20T08:04:39.310-04:00">ACCEPTED</status_change>
            <modified comment="Noticed that this vulnerability only applies to Microsoft .NET Framework 2.0, so removed the part of the criteria related to .NET Famework 1.0" date="2007-09-13T00:00:00.107-04:00">
              <contributor organization="Secure Elements, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2007-09-13T11:07:56.939-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:11.444-04:00">ACCEPTED</status_change>
            <modified comment="Corrected criteria to check for System.web.dll version is less than 2.0.50727.832 when looking for the vuln in .NET 2.0" date="2007-10-04T10:18:00.560-04:00">
              <contributor organization="Secure Elements, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2007-10-04T10:20:49.574-04:00">INTERIM</status_change>
            <status_change date="2007-10-22T08:53:25.503-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="An affected operating system with .net 2.0 and a vulnerable dll exists">
        <criteria operator="OR" comment="An affected operating system is installed">
          <extend_definition comment="Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Microsoft Windows Server 2003 SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <extend_definition comment="Microsoft Windows Server 2003 SP2 is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          <extend_definition comment="Microsoft Windows Server 2003 (x64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
        </criteria>
        <extend_definition comment=".NET 2.0 is Installed" definition_ref="oval:org.mitre.oval:def:1934"/>
        <criterion comment="System.web.dll version is less than 2.0.50727.832" test_ref="oval:org.mitre.oval:tst:3378"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1934" version="6" class="inventory">
      <metadata>
        <title>Microsoft .NET Framework 2.0 (Original RTM or later) is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft .NET Framework 2.0</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:.net_framework:2.0"/>
        <description>Microsoft .NET Framework 2.0 (Original RTM or later) is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-11T18:34:24">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-07-16T09:52:05.115-04:00">DRAFT</status_change>
            <status_change date="2007-08-01T22:26:15.137-04:00">INTERIM</status_change>
            <status_change date="2007-08-20T08:04:39.577-04:00">ACCEPTED</status_change>
            <status_change date="2007-09-13T11:07:56.103-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1934 - Updated to check registry keys instead of version of DLL." date="2011-01-13T14:14:00.592-05:00">
              <contributor organization="The MITRE Corporation">Nate Przybyszewski</contributor>
            </modified>
            <status_change date="2011-01-13T14:16:15.689-05:00">INTERIM</status_change>
            <status_change date="2011-01-31T04:00:14.357-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1934 - MS Oct 2013 bulletin ms13-081-n-082 (.Net 2 inventory CPE added)" date="2013-10-17T11:45:00.437-04:00">
              <contributor organization="SecPod Technologies">Sharath S</contributor>
            </modified>
            <status_change date="2013-10-17T11:49:24.854-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:02.396-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Is the Microsoft .NET Framework 2.0 installed" test_ref="oval:org.mitre.oval:tst:42091"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1857" version="6" class="vulnerability">
      <metadata>
        <title>RASMAN Registry Corruption Vulnerability (Win2K)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2371" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2371"/>
        <description>Buffer overflow in the Remote Access Connection Manager service (RASMAN) service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote unauthenticated or authenticated attackers to execute arbitrary code via certain crafted "RPC related requests," that lead to registry corruption and stack corruption, aka the "RASMAN Registry Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:35.404-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:35.183-04:00">ACCEPTED</status_change>
            <modified comment="Fixed regex in ste:2889.  Implemented by Matthew Wojcik." date="2007-03-06T18:19:00.507-05:00">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2007-03-06T18:21:12.493-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:06.640-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1857 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:05:31.897-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:01:59.168-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="the version of rasmans.dll is less than 5.0.2195.7093" test_ref="oval:org.mitre.oval:tst:747"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1856" version="1" class="vulnerability">
      <metadata>
        <title>Windows Active Directory Denial of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3028" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3028"/>
        <description>The LDAP service in Windows Active Directory in Microsoft Windows 2000 Server SP4 does not properly check "the number of convertible attributes", which allows remote attackers to cause a denial of service (service unavailability) via a crafted LDAP request, related to "client sent LDAP request logic," aka "Windows Active Directory Denial of Service Vulnerability".  NOTE: this is probably a different issue than CVE-2007-0040.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-10T18:34:24">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-07-11T14:48:25.350-04:00">DRAFT</status_change>
            <modified comment="Removed Windows Server 2003 criterion as this CVE only affects Windows 2000" date="2007-07-16T13:39:00.352-04:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2007-08-01T22:26:14.815-04:00">INTERIM</status_change>
            <status_change date="2007-08-20T08:04:39.090-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Windows 2000 SP4" operator="AND">
          <extend_definition comment="Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="ntdsa.dll version is less than 5.0.2195.7135" test_ref="oval:org.mitre.oval:tst:3970"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1855" version="3" class="vulnerability">
      <metadata>
        <title>Mozilla Cross-site JavaScript Injection Using Event Handlers</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1741" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1741"/>
        <description>Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to inject arbitrary Javascript into other sites by (1) "using a modal alert to suspend an event handler while a new page is being loaded", (2) using eval(), and using certain variants involving (3) "new Script;" and (4) using window.__proto__ to extend eval, aka "cross-site JavaScript injection".</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-07T09:05:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:35.230-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:1133" date="2007-02-26T08:08:00.208-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-26T08:09:12.530-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:1135" date="2007-02-26T08:21:00.993-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:1136" date="2007-02-26T08:24:00.848-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:1138" date="2007-02-26T08:25:00.405-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:2283" date="2007-02-26T08:29:00.407-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:2284" date="2007-02-26T08:30:00.724-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:17:06.364-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:881" date="2007-04-23T12:05:00.811-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:12:50.191-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:882" date="2007-04-23T12:05:00.939-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in obj:883" date="2007-04-23T12:05:00.804-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in obj:1385" date="2007-04-23T12:05:00.430-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:11:00.102-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1268"/>
          <criterion comment="Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1267"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Thunderbird version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1266"/>
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1265"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.12 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1264"/>
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1263"/>
        </criteria>
        <criteria operator="AND" comment="A pre-release of SeaMonkey 1.0 is installed">
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2439"/>
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2438"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1854" version="3" class="vulnerability">
      <metadata>
        <title>Windows Animated Cursor Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0038" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0038"/>
        <description>Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a large length value in the second (or later) anih block of a RIFF .ANI, cur, or .ico file, which results in memory corruption when processing cursors, animated cursors, and icons, a variant of CVE-2005-0416, as originally demonstrated using Internet Explorer 6 and 7. NOTE: this might be a duplicate of CVE-2007-1765; if so, then CVE-2007-0038 should be preferred.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-04-09T09:49:32">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-04-09T11:20:00.000-05:00">DRAFT</status_change>
            <status_change date="2007-04-25T19:52:20.341-04:00">INTERIM</status_change>
            <modified comment="Altered S03 section of criteria to reference proper Gdi32.dll file versions for S03,SP1 and S03,SP2." date="2007-04-26T14:12:00.001-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-05-23T15:05:33.594-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1854 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:06:52.119-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:22.355-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="gdi32.dll version is less than 5.0.2195.7133" test_ref="oval:org.mitre.oval:tst:3337"/>
        </criteria>
        <criteria operator="AND" comment="Windows XP SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="gdi32.dll version is less than 5.1.2600.3099" test_ref="oval:org.mitre.oval:tst:3215"/>
        </criteria>
        <criteria operator="AND" comment="S03-Gold">
          <extend_definition comment="Microsoft Windows Server 2003 (x86) Gold is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="gdi32.dll version is less than 5.2.3790.651" test_ref="oval:org.mitre.oval:tst:4019"/>
        </criteria>
        <criteria operator="AND" comment="S03,SP1">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="gdi32.dll version is less than 5.2.3790.2892" test_ref="oval:org.mitre.oval:tst:3548"/>
        </criteria>
        <criteria operator="AND" comment="S03,SP2">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <criterion comment="gdi32.dll version is less than 5.2.3790.4033" test_ref="oval:org.mitre.oval:tst:3612"/>
        </criteria>
        <criteria operator="AND" comment="Windows Vista">
          <extend_definition comment="Microsoft Windows Vista is installed" definition_ref="oval:org.mitre.oval:def:228"/>
          <criterion comment="the version of user32.dll is less than 6.0.6000.16438" test_ref="oval:org.mitre.oval:tst:3182"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1850" version="7" class="vulnerability">
      <metadata>
        <title>SMB Invalid Handle Vulnerability (Win2K)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2374" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2374"/>
        <description>The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows local users to cause a denial of service (hang) by calling the MrxSmbCscIoctlCloseForCopyChunk with the file handle of the shadow device, which results in a deadlock, aka the "SMB Invalid Handle Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:34.969-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:34.163-04:00">ACCEPTED</status_change>
            <modified comment="Fixed regex in ste:2889.  Implemented by Matthew Wojcik." date="2007-03-06T18:19:00.507-05:00">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2007-03-06T18:21:16.296-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:06.141-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1850 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:06:42.717-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:01:58.550-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="the version of mrxsmb.sys is less than 5.0.2195.7097" test_ref="oval:org.mitre.oval:tst:685"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1848" version="3" class="vulnerability">
      <metadata>
        <title>Mozilla Mozilla Firefox Tag Order Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0749" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0749"/>
        <description>nsHTMLContentSink.cpp in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors involving a "particular sequence of HTML tags" that leads to memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-07T09:05:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:34.648-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:1133" date="2007-02-26T08:08:00.208-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-26T08:09:15.206-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:1135" date="2007-02-26T08:21:00.993-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:1136" date="2007-02-26T08:24:00.848-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:1138" date="2007-02-26T08:25:00.405-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:2283" date="2007-02-26T08:29:00.407-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:2284" date="2007-02-26T08:30:00.724-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:17:05.869-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:881" date="2007-04-23T12:05:00.811-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:12:53.321-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:882" date="2007-04-23T12:05:00.939-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in obj:883" date="2007-04-23T12:05:00.804-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in obj:1385" date="2007-04-23T12:05:00.430-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:10:59.612-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1268"/>
          <criterion comment="Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1267"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Thunderbird version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1266"/>
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1265"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.12 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1264"/>
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1263"/>
        </criteria>
        <criteria operator="AND" comment="A pre-release of SeaMonkey 1.0 is installed">
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2439"/>
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2438"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1845" version="8" class="vulnerability">
      <metadata>
        <title>Exception Handling Memory Corruption Vulnerability (Win2k)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2218" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2218"/>
        <description>Unspecified vulnerability in Internet Explorer 6.0 on Microsoft Windows XP SP2 allows remote attackers to execute arbitrary code via "exceptional conditions" that trigger memory corruption, as demonstrated using an exception handler and nested object tags, a variant of CVE-2006-1992.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:34.389-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:33.395-04:00">ACCEPTED</status_change>
            <modified comment="Fixed ste:2614: set datatype to version.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:54:00.319-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:59:44.345-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:02.161-05:00">ACCEPTED</status_change>
            <modified comment="Fixed regex in ste:2889.  Implemented by Matthew Wojcik." date="2007-03-06T18:19:00.507-05:00">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2007-03-06T18:21:10.084-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:05.660-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:46:45.132-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:01:57.372-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:59.798-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:24.392-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3841.1900" negate="false" test_ref="oval:org.mitre.oval:tst:957"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1829" version="3" class="vulnerability">
      <metadata>
        <title>Mozilla Crashes with Evidence of Memory Corruption (RegEx)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1737" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1737"/>
        <description>Integer overflow in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary bytecode via JavaScript with a large regular expression.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-07T09:05:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:33.329-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:1133" date="2007-02-26T08:08:00.208-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-26T08:09:12.731-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:1135" date="2007-02-26T08:21:00.993-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:1136" date="2007-02-26T08:24:00.848-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:1138" date="2007-02-26T08:25:00.405-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:2283" date="2007-02-26T08:29:00.407-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:2284" date="2007-02-26T08:30:00.724-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:17:05.049-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:881" date="2007-04-23T12:05:00.811-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:12:50.443-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:882" date="2007-04-23T12:05:00.939-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in obj:883" date="2007-04-23T12:05:00.804-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in obj:1385" date="2007-04-23T12:05:00.430-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:10:59.155-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1268"/>
          <criterion comment="Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1267"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Thunderbird version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1266"/>
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1265"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.12 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1264"/>
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1263"/>
        </criteria>
        <criteria operator="AND" comment="A pre-release of SeaMonkey 1.0 is installed">
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2439"/>
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2438"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1820" version="5" class="vulnerability">
      <metadata>
        <title>Windows Media Player PNG Vulnerability (v9.0)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Media Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0025" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0025"/>
        <description>Stack-based buffer overflow in Microsoft Windows Media Player 9 and 10 allows remote attackers to execute arbitrary code via a PNG image with a large chunk size.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:32.741-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:28.915-04:00">ACCEPTED</status_change>
            <modified comment="Modified ste:705: altered regex to match on a double zero in the minor field of the version, and also added an initial anchor.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:23:00.679-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:25:34.938-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:01.980-05:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:746" date="2007-03-06T08:04:00.424-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-06T08:05:13.164-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:04.837-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:746 - added trailing $ to regexs" date="2011-10-31T09:26:00.646-04:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2011-10-31T09:31:17.158-04:00">INTERIM</status_change>
            <status_change date="2011-11-21T04:13:08.315-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Media Player 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:786"/>
        <criterion comment="Windows Media Player 10 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:833"/>
        <criterion comment="the version of wmp.dll is less than 9.0.0.3349" negate="false" test_ref="oval:org.mitre.oval:tst:706"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1818" version="3" class="vulnerability">
      <metadata>
        <title>Exchange 2000,SP4 Calendar Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Exchange Server</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0027" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0027"/>
        <description>Unspecified vulnerability in Microsoft Exchange allows remote attackers to execute arbitrary code via e-mail messages with crafted (1) vCal or (2) iCal Calendar properties.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-10T03:16:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:32.600-04:00">ACCEPTED</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.427-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-10-25T16:50:41.619-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:01:02.102-05:00">ACCEPTED</status_change>
            <modified comment="References registry value for Common Files directory due to multilingual support" date="2008-04-14T11:07:00.679-04:00">
              <contributor organization="GFI Software">Clifford Farrugia</contributor>
            </modified>
            <status_change date="2008-04-14T12:26:44.953-04:00">INTERIM</status_change>
            <status_change date="2008-05-05T04:00:14.118-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Exchange Server 2000,SP3 is installed." negate="false" test_ref="oval:org.mitre.oval:tst:992"/>
        <criterion comment="cdoex.dll is less than 6.0.6618.4" negate="false" test_ref="oval:org.mitre.oval:tst:707"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1816" version="8" class="vulnerability">
      <metadata>
        <title>MsgBox (CSRSS) Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-6696" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6696"/>
        <description>Double free vulnerability in Microsoft Windows 2000, XP, 2003, and Vista allows local users to gain privileges by calling the MessageBox function with a MB_SERVICE_NOTIFICATION message with crafted data, which sends a HardError message to Client/Server Runtime Server Subsystem (CSRSS) process, which is not properly handled when invoking the UserHardError and GetHardErrorText functions in WINSRV.DLL.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-04-10T16:31:02">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-04-10T16:31:02.000-05:00">DRAFT</status_change>
            <status_change date="2007-04-25T19:52:19.692-04:00">INTERIM</status_change>
            <modified comment="Fixed typo in Vista criteria block: changed reference to extended def:521 (XP SP2) to def:228 (Vista)." date="2007-04-26T10:56:00.022-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <modified comment="Fixed the version of winsrv.dll to 6.0.6000.16445 for Vista." date="2007-05-03T15:48:00.763-04:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2007-05-23T15:05:32.840-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1816 - Update to MS07-021" date="2011-04-07T11:19:00.389-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-04-07T11:21:44.255-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1816 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-09T04:01:21.292-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1816 - Correcting incorrect references to 64-bit Itanium XP." date="2012-08-23T17:47:00.168-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-08-23T17:51:56.307-04:00">INTERIM</status_change>
            <status_change date="2012-09-10T04:00:41.999-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1816 - Multiple updates to several Windows OVAL entities. Includes CPE, title, and description updates. Fixed incorrectly referenced criteria. Added new criteria, fixed criteria checks, and improved criteria comments for several definitions." date="2012-11-02T20:20:00.882-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-11-02T20:24:47.741-04:00">INTERIM</status_change>
            <status_change date="2012-11-19T04:00:32.201-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="The version of winsrv.dll is less than 5.0.2195.7135." test_ref="oval:org.mitre.oval:tst:3935"/>
        </criteria>
        <criteria operator="AND" comment="Windows XP SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="The version of winsrv.dll is less than 5.1.2600.3103." test_ref="oval:org.mitre.oval:tst:42142"/>
        </criteria>
        <criteria operator="AND" comment="Windows XP SP1 x64">
          <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="The version of winsrv.dll is less than 5.2.3790.2902." test_ref="oval:org.mitre.oval:tst:3229"/>
        </criteria>
        <criteria operator="AND" comment="Windows XP SP2 x64">
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          <criterion comment="The version of winsrv.dll is less than 5.2.3790.4043." test_ref="oval:org.mitre.oval:tst:80250"/>
        </criteria>
        <criteria operator="AND" comment="Windows Server 2003 Gold versions">
          <criteria operator="OR" comment="Windows Server 2003 x86/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (x86) Gold is installed" definition_ref="oval:org.mitre.oval:def:165"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <criterion comment="The version of winsrv.dll is less than 5.2.3790.658." test_ref="oval:org.mitre.oval:tst:3288"/>
        </criteria>
        <criteria operator="AND" comment="Windows Server 2003 SP1 versions">
          <criteria operator="OR" comment="Windows Server 2003 x86/x64/ia64 SP1">
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:4386"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
          </criteria>
          <criterion comment="The version of winsrv.dll is less than 5.2.3790.2902." test_ref="oval:org.mitre.oval:tst:3229"/>
        </criteria>
        <criteria operator="AND" comment="Windows Server 2003 Service Pack 2 x86/x64/ia64 and winsrv.dll">
          <criteria operator="OR" comment="Windows Server 2003 Service Pack 2 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="The version of winsrv.dll is less than 5.2.3790.4043." test_ref="oval:org.mitre.oval:tst:80250"/>
        </criteria>
        <criteria operator="AND" comment="Windows Vista">
          <criteria operator="OR" comment="Windows Vista x86/x64">
            <extend_definition comment="Microsoft Windows Vista is installed" definition_ref="oval:org.mitre.oval:def:228"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="GRD/LDR version Check">
            <criterion comment="The version of winsrv.dll is less than 6.0.6000.16445." test_ref="oval:org.mitre.oval:tst:3701"/>
            <criteria operator="AND" comment="LDR version check">
              <criterion comment="the version of winsrv.dll is greater than or equal 6.0.6000.20000" test_ref="oval:org.mitre.oval:tst:80223"/>
              <criterion comment="the version of winsrv.dll is less than 6.0.6000.20544" test_ref="oval:org.mitre.oval:tst:79826"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1811" version="3" class="vulnerability">
      <metadata>
        <title>Mozilla Secure-site Spoof (requires security warning dialog)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1740" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1740"/>
        <description>Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to spoof secure site indicators such as the locked icon by opening the trusted site in a popup window, then changing the location to a malicious site.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-07T09:05:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:32.430-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:1133" date="2007-02-26T08:08:00.208-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-26T08:09:16.615-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:1138" date="2007-02-26T08:25:00.405-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:2283" date="2007-02-26T08:29:00.407-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:2284" date="2007-02-26T08:30:00.724-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:17:04.624-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:881" date="2007-04-23T12:05:00.811-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:12:54.834-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:883" date="2007-04-23T12:05:00.804-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in obj:1385" date="2007-04-23T12:05:00.430-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:10:58.597-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1268"/>
          <criterion comment="Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1267"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.12 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1264"/>
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1263"/>
        </criteria>
        <criteria operator="AND" comment="A pre-release of SeaMonkey 1.0 is installed">
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2439"/>
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2438"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1808" version="3" class="vulnerability">
      <metadata>
        <title>Windows 2000 Negotiate Security Software Provider Denial of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Negotiate SSP interface</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0119" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0119"/>
        <description>The Negotiate Security Software Provider (SSP) interface in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service (crash from null dereference) or execute arbitrary code via a crafted SPNEGO NegTokenInit request during authentication protocol selection.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-06-30T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-12T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-01-13T12:00:00.000-04:00" comment="modified wft-345 - Addded a space in the registry key component of the file path">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2005-01-20T01:26:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected to use a forward slash as the separator in the key." date="2007-05-07T15:59:00.728-04:00">
              <contributor organization="Secure Elements, Inc.">Glenn Strickland</contributor>
            </modified>
            <status_change date="2007-05-07T16:00:38.839-04:00">INTERIM</status_change>
            <status_change date="2007-05-23T15:05:32.274-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
          <criterion comment="The version of Ipnathlp.dll is less than 5.0.2195.6902" negate="false" test_ref="oval:org.mitre.oval:tst:710"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Negotiate is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:709"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1800" version="8" class="vulnerability">
      <metadata>
        <title>CSS Cross-Domain Information Disclosure Vulnerability (Win2K)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-4089" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4089"/>
        <description>Microsoft Internet Explorer allows remote attackers to bypass cross-domain security restrictions and obtain sensitive information by using the @import directive to download files from other domains that are not valid Cascading Style Sheets (CSS) files, as demonstrated using Google Desktop, aka "CSSXSS" and "CSS Cross-Domain Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:31.754-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:26.731-04:00">ACCEPTED</status_change>
            <modified comment="Fixed ste:2614: set datatype to version.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:54:00.319-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:59:43.526-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:01.455-05:00">ACCEPTED</status_change>
            <modified comment="Fixed regex in ste:2889.  Implemented by Matthew Wojcik." date="2007-03-06T18:19:00.507-05:00">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2007-03-06T18:21:09.200-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:04.018-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:44:05.764-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:01:52.740-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:39.909-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:24.264-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3841.1900" negate="false" test_ref="oval:org.mitre.oval:tst:957"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:180" version="7" class="vulnerability">
      <metadata>
        <title>Windows 2000,SP4 Remote Desktop Protocol (RDP) DoS Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1218" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1218"/>
        <description>The Microsoft Windows kernel in Microsoft Windows 2000 Server, Windows XP, and Windows Server 2003 allows remote attackers to cause a denial of service (crash) via crafted Remote Desktop Protocol (RDP) requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:40:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:31.531-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:26.291-04:00">ACCEPTED</status_change>
            <modified comment="Replaced tst:3652 with tst:3073 and updated comments" date="2010-12-02T11:47:00.010-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-12-02T11:48:17.080-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:36.117-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:180 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:06:29.854-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:01:52.440-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" test_ref="oval:org.mitre.oval:tst:3381"/>
          <criterion comment="SP4 or later Installed" test_ref="oval:org.mitre.oval:tst:3073"/>
        </criteria>
        <criterion comment="the version of rdpwd.sys is less than 5.0.2195.7055" test_ref="oval:org.mitre.oval:tst:3633"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1797" version="3" class="vulnerability">
      <metadata>
        <title>Font Rasterizer Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1213" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1213"/>
        <description>The TrueType Fonts rasterizer in Microsoft Windows 2000 SP4 allows local users to gain privileges via crafted TrueType fonts, which result in an uninitialized function pointer.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-04-09T09:49:32">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-04-09T11:20:00.000-05:00">DRAFT</status_change>
            <status_change date="2007-04-25T19:52:19.270-04:00">INTERIM</status_change>
            <modified comment="Removed criteria sections and affected.platform elements for XP, S03, and Vista. MS07-017 says they are not affected." date="2007-04-26T14:22:00.824-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-05-23T15:05:31.643-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1797 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:05:57.439-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:20.612-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
        <criterion comment="gdi32.dll version is less than 5.0.2195.7133" test_ref="oval:org.mitre.oval:tst:3337"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1791" version="7" class="vulnerability">
      <metadata>
        <title>Microsoft Outlook Express 6 (S03,SP1) WAB Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Outlook Express</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0014" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0014"/>
        <description>Buffer overflow in Microsoft Outlook Express 5.5 and 6 allows remote attackers to execute arbitrary code via a crafted Windows Address Book (WAB) file containing "certain Unicode strings" and modified length values.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-30T04:13:00.000-04:00" comment="Replaced periods with commas used to check Outlook Version in ste:1485.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <modified date="2006-10-30T12:13:00.000-04:00" comment="Added beginning anchor to ste:1485 to eliminate potential mid-string matches.  Modified by Matthew Wojcik.">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2006-10-30T12:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-11-14T08:57:56.156-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:1485 - Correction to pattern match in ste:1485." date="2010-12-27T19:49:00.448-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <status_change date="2010-12-27T19:58:09.375-05:00">INTERIM</status_change>
            <status_change date="2011-01-17T04:00:18.824-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:46:34.506-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:01:50.849-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Windows Server 2003 is installed" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003/Vista service pack 1 is installed" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="Microsoft Outlook Express 6 for Windows XP/2003 is installed" test_ref="oval:org.mitre.oval:tst:1633"/>
        <criterion comment="the version of inetcomm.dll is less than 6.0.3790.2663" test_ref="oval:org.mitre.oval:tst:1632"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1787" version="7" class="vulnerability">
      <metadata>
        <title>IP Source Route Vulnerability (Win2K)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2379" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2379"/>
        <description>Buffer overflow in the TCP/IP Protocol driver in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote attackers to execute arbitrary code via unknown vectors related to IP source routing.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:30.933-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:25.059-04:00">ACCEPTED</status_change>
            <modified comment="Fixed regex in ste:2889.  Implemented by Matthew Wojcik." date="2007-03-06T18:19:00.507-05:00">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2007-03-06T18:21:12.294-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:03.627-04:00">ACCEPTED</status_change>
            <modified comment="Changing deprecated obj:563 to obj:588" date="2010-01-12T15:23:00.503-05:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2010-01-12T15:24:10.742-05:00">INTERIM</status_change>
            <status_change date="2010-02-01T04:00:06.500-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1787 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:05:34.758-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:01:50.242-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="the version of Tcpip.sys is less than 5.0.2195.7087" test_ref="oval:org.mitre.oval:tst:718"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1785" version="5" class="vulnerability" deprecated="true">
      <metadata>
        <title>DEPRECATED: Microsoft JScript Memory Corruption Vulnerability (Win2K w/ JScript 5.6)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1313" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1313"/>
        <description>Microsoft JScript 5.1, 5.5, and 5.6 on Windows 2000 SP4, and 5.6 on Windows XP, Server 2003, Windows 98 and Windows Me, will "release objects early" in certain cases, which results in memory corruption and allows remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:30.792-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:24.604-04:00">ACCEPTED</status_change>
            <modified comment="Fixed regex in ste:2889.  Implemented by Matthew Wojcik." date="2007-03-06T18:19:00.507-05:00">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2007-03-06T18:21:15.987-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:03.450-04:00">ACCEPTED</status_change>
            <modified comment="Use def:1067 instead, which covers all appropriate versions of the DLL" date="2011-01-20T10:31:42.940-05:00">
              <contributor organization="The MITRE Corporation">Nate Przybyszewski</contributor>
            </modified>
            <status_change date="2011-01-20T10:31:42.940-05:00">DEPRECATED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="the version of Jscript.dll is greater than or equal to 5.6.0.0" negate="false" test_ref="oval:org.mitre.oval:tst:719"/>
        <criterion comment="the version of Jscript.dll is less than 5.6.0.8831" negate="false" test_ref="oval:org.mitre.oval:tst:1206"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1784" version="6" class="vulnerability">
      <metadata>
        <title>VML Buffer Overrun Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1749" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1749"/>
        <description>Integer underflow in the CDownloadSink class code in the Vector Markup Language (VML) component (VGX.DLL), as used in Internet Explorer 5.01, 6, and 7 allows remote attackers to execute arbitrary code via compressed content with an invalid buffer size, which triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-15T09:28:35">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-08-15T15:55:13.262-04:00">DRAFT</status_change>
            <modified comment="Added version datatype to file_state version element. Altered oval:org.mitre.oval:ste:3337" date="2007-08-23T14:13:00.710-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="Added version datatype to file_state version element. Altered oval:org.mitre.oval:ste:3412" date="2007-08-23T14:13:00.089-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="Added version datatype to file_state version element. Altered oval:org.mitre.oval:ste:3947" date="2007-08-23T14:13:00.855-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="Added version datatype to file_state version element. Altered oval:org.mitre.oval:ste:3185" date="2007-08-23T14:13:00.875-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="Added version datatype to file_state version element. Altered oval:org.mitre.oval:ste:3135" date="2007-08-23T14:13:00.637-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="Added version datatype to file_state version element. Altered oval:org.mitre.oval:ste:3490" date="2007-08-23T14:13:00.490-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="Added version datatype to file_state version element. Altered oval:org.mitre.oval:ste:3639" date="2007-08-23T14:13:00.049-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-09-10T14:45:26.068-04:00">INTERIM</status_change>
            <status_change date="2007-09-27T08:57:41.733-04:00">ACCEPTED</status_change>
            <modified comment="References registry value for Common Files directory due to multilingual support" date="2008-04-14T11:07:00.466-04:00">
              <contributor organization="GFI Software">Clifford Farrugia</contributor>
            </modified>
            <status_change date="2008-04-14T12:28:16.294-04:00">INTERIM</status_change>
            <status_change date="2008-05-05T04:00:13.352-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1784 - Correcting incorrect references to 64-bit Itanium XP." date="2012-08-23T17:47:00.168-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-08-23T17:52:33.419-04:00">INTERIM</status_change>
            <status_change date="2012-09-10T04:00:41.192-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:58.858-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:23.873-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 5.01,SP4 on Win2k,SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="the version of vgx.dll is less than 5.0.3854.2500" test_ref="oval:org.mitre.oval:tst:3208"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win 2k, SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the version of vgx.dll is less than 6.0.2800.1599" test_ref="oval:org.mitre.oval:tst:3469"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win XP SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of vgx.dll is less than 6.0.2900.3164" test_ref="oval:org.mitre.oval:tst:3856"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 on Win XP SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="the version of vgx.dll is less than 7.0.6000.20628" test_ref="oval:org.mitre.oval:tst:4182"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win XP SP1 (64-bit)">
          <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of vgx.dll is less than 6.0.3790.2962" test_ref="oval:org.mitre.oval:tst:4049"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win XP SP2 (64-bit)">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of vgx.dll is less than 6.0.3790.4106" test_ref="oval:org.mitre.oval:tst:3422"/>
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 on Win XP (64-bit)">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="the version of vgx.dll is less than 7.0.6000.20628" test_ref="oval:org.mitre.oval:tst:4182"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win S03 SP1">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of vgx.dll is less than 6.0.3790.2962" test_ref="oval:org.mitre.oval:tst:4049"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win S03 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of vgx.dll is less than 6.0.3790.4106" test_ref="oval:org.mitre.oval:tst:3422"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 on S03">
          <criteria operator="OR" comment="Windows XP (64-bit,SP1) or Server 2003 (SP1) is installed">
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="the version of vgx.dll is less than 7.0.6000.20628" test_ref="oval:org.mitre.oval:tst:4182"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 on Vista">
          <extend_definition comment="Microsoft Windows Vista is installed" definition_ref="oval:org.mitre.oval:def:228"/>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="the version of vgx.dll is less than 7.0.6000.16513" test_ref="oval:org.mitre.oval:tst:4196"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1780" version="2" class="vulnerability">
      <metadata>
        <title>Microsoft Outlook Express 5.5 WAB Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Outlook Express</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0014" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0014"/>
        <description>Buffer overflow in Microsoft Outlook Express 5.5 and 6 allows remote attackers to execute arbitrary code via a crafted Windows Address Book (WAB) file containing "certain Unicode strings" and modified length values.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-30T04:13:00.000-04:00" comment="Replaced periods with commas used to check Outlook Version  in ste:649.  Modified by Harvey Rubinovitz.">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <modified date="2006-10-30T12:13:00.000-04:00" comment="Added beginning anchor to ste:649 to eliminate potential mid-string matches.  Modified by Matthew Wojcik.">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2006-10-30T12:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-11-14T08:57:55.387-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Microsoft Outlook Express 5.5 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:723"/>
        <criterion comment="the version of inetcomm.dll is less than 5.50.4963.1700" negate="false" test_ref="oval:org.mitre.oval:tst:722"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:178" version="3" class="vulnerability">
      <metadata>
        <title>IE v5.5 Improper Cross Domain Security Validation with Dialog Box</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1326" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1326"/>
        <description>Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model to run malicious script or arbitrary programs via dialog boxes, aka "Improper Cross Domain Security Validation with dialog box."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-27T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:37.822-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:23.739-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Internet Explorer 5.5 Installed">
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3078"/>
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3077"/>
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3076"/>
          <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
        </criteria>
        <criterion comment="the version of mshtml.dll is less than 5.50.4923.2500" negate="false" test_ref="oval:org.mitre.oval:tst:2849"/>
        <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3013"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1778" version="6" class="vulnerability">
      <metadata>
        <title>Microsoft Windows 2000 Microsoft Data Access Components RDS.Dataspace Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Data Access Components</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0003" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0003"/>
        <description>Unspecified vulnerability in the RDS.Dataspace ActiveX control, which is contained in ActiveX Data Objects (ADO) and distributed in Microsoft Data Access Components (MDAC) 2.7 and 2.8, allows remote attackers to execute arbitrary code via unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed regex in ste:2889.  Implemented by Matthew Wojcik." date="2007-03-06T18:19:00.507-05:00">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2007-03-06T18:21:15.739-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:03.149-04:00">ACCEPTED</status_change>
            <modified comment="References registry value for Common Files directory due to multilingual support" date="2008-04-14T11:07:00.270-04:00">
              <contributor organization="GFI Software">Clifford Farrugia</contributor>
            </modified>
            <status_change date="2008-04-14T12:27:07.673-04:00">INTERIM</status_change>
            <status_change date="2008-05-05T04:00:12.794-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:46:15.339-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:01:48.563-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criteria operator="OR" comment="Microsoft Data Access Components 2.5(SP3), 2.7(SP1), 2.8, or 2.8(SP1) is installed without patches for MS06-014">
          <criteria operator="AND" comment="Microsoft Data Access Components 2.5,SP3 with msadco.dll version less than 2.53.6306.0">
            <criterion comment="Microsoft Data Access Components 2.5 (SP3) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:729"/>
            <criterion comment="the version of msadco.dll is less than 2.53.6306.0" negate="false" test_ref="oval:org.mitre.oval:tst:728"/>
          </criteria>
          <criteria operator="AND" comment="Microsoft Data Access Components 2.7,SP1 with msadco.dll version less than 2.71.9053.0">
            <criterion comment="Microsoft Data Access Components 2.7 (SP1) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2382"/>
            <criterion comment="the version of msadco.dll is less than 2.71.9053.0" negate="false" test_ref="oval:org.mitre.oval:tst:727"/>
          </criteria>
          <criteria operator="AND" comment="Microsoft Data Access Components 2.8 with msadco.dll version less than 2.80.1062.0000">
            <criterion comment="Microsoft Data Access Components 2.8 (RTM) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2363"/>
            <criterion comment="the version of msadco.dll is less than 2.80.1062.0000" negate="false" test_ref="oval:org.mitre.oval:tst:726"/>
          </criteria>
          <criteria operator="AND" comment="Microsoft Data Access Components 2.8,SP1 with msadco.dll version less than 2.81.1124.0">
            <criterion comment="Microsoft Data Access Components 2.8 (SP1) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:725"/>
            <criterion comment="the version of msadco.dll is less than 2.81.1124.0" negate="false" test_ref="oval:org.mitre.oval:tst:724"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1775" version="7" class="vulnerability">
      <metadata>
        <title>Address Bar Spoofing Vulnerability (2K/XP)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2384" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2384"/>
        <description>Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remote attackers to conduct spoofing and phishing attacks by using a modal browser window in a way that preserves the original address bar and trusted UI of a trusted site, even after the browser has been navigated to a malicious site, aka the "Address Bar Spoofing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:30.316-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:23.671-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:46:06.143-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:00.443-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:46:16.553-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:01:47.816-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:54.693-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:23.625-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Win2K or XP,SP1 is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2800.1555" negate="false" test_ref="oval:org.mitre.oval:tst:802"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1774" version="8" class="vulnerability">
      <metadata>
        <title>IE5 HTA Execution Vulnerability (Win2K)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1388" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1388"/>
        <description>Unspecified vulnerability in Microsoft Internet Explorer 6.0 allows remote attackers to execute HTA files via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Modified ste:831: altered regex to match on a double zero in the minor field of the version, and also added an initial anchor.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:27:00.230-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:28:37.192-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:00.250-05:00">ACCEPTED</status_change>
            <modified comment="Fixed regex in ste:2889.  Implemented by Matthew Wojcik." date="2007-03-06T18:19:00.507-05:00">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2007-03-06T18:21:08.609-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:02.902-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:46:17.959-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:01:47.456-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:54.878-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:23.505-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="Internet Explorer 5.01 (any patch level) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:927"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3839.2200" negate="false" test_ref="oval:org.mitre.oval:tst:926"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1771" version="8" class="vulnerability">
      <metadata>
        <title>Microsoft Outlook Express 6 (S03-Gold, Itanium) WAB Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Outlook Express</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0014" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0014"/>
        <description>Buffer overflow in Microsoft Outlook Express 5.5 and 6 allows remote attackers to execute arbitrary code via a crafted Windows Address Book (WAB) file containing "certain Unicode strings" and modified length values.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-30T04:13:00.000-04:00" comment="Replaced periods with commas used to check Outlook Version in ste:1485.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <modified date="2006-10-30T12:13:00.000-04:00" comment="Added beginning anchor to ste:1485 to eliminate potential mid-string matches.  Modified by Matthew Wojcik.">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2006-10-30T12:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-11-14T08:57:54.489-05:00">ACCEPTED</status_change>
            <modified comment="Removed unneeded ste:2282 from tst:2437. Deprecated ste:2282 since it is no longer used." date="2007-01-12T07:06:00.595-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-01-12T07:09:02.163-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:00.015-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:1485 - Correction to pattern match in ste:1485." date="2010-12-27T19:49:00.448-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <status_change date="2010-12-27T19:58:09.197-05:00">INTERIM</status_change>
            <status_change date="2011-01-17T04:00:18.420-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:46:18.932-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:01:46.627-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Windows Server 2003 is installed" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion negate="true" comment="Win2K/XP/2003 is patched" test_ref="oval:org.mitre.oval:tst:2437"/>
        <criterion comment="a version of Windows for the ia64 architecture is installed" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="Microsoft Outlook Express 6 for Windows XP/2003 is installed" test_ref="oval:org.mitre.oval:tst:1633"/>
        <criterion comment="the version of inetcomm.dll is less than 6.0.3790.504" test_ref="oval:org.mitre.oval:tst:731"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1769" version="4" class="vulnerability">
      <metadata>
        <title>Microsoft Outlook Express 6 (64-bit XP) WAB Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Outlook Express</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0014" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0014"/>
        <description>Buffer overflow in Microsoft Outlook Express 5.5 and 6 allows remote attackers to execute arbitrary code via a crafted Windows Address Book (WAB) file containing "certain Unicode strings" and modified length values.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-30T04:13:00.000-04:00" comment="Replaced periods with commas used to check Outlook Version in ste:1485.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <modified date="2006-10-30T12:13:00.000-04:00" comment="Added beginning anchor to ste:1485 to eliminate potential mid-string matches.  Modified by Matthew Wojcik.">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2006-10-30T12:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-11-14T08:57:53.493-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:1485 - Correction to pattern match in ste:1485." date="2010-12-27T19:49:00.448-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <status_change date="2010-12-27T19:58:09.430-05:00">INTERIM</status_change>
            <status_change date="2011-01-17T04:00:18.065-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Windows XP is installed" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="a version of Windows for the ia64 architecture is installed" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="Microsoft Outlook Express 6 for Windows XP/2003 is installed" test_ref="oval:org.mitre.oval:tst:1633"/>
        <criterion comment="the version of inetcomm.dll is less than 6.0.3790.2663" test_ref="oval:org.mitre.oval:tst:732"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1767" version="8" class="vulnerability">
      <metadata>
        <title>COM Object Instantiation Memory Corruption Vulnerability (Win2K)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1303" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1303"/>
        <description>Multiple unspecified vulnerabilities in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allow remote attackers to execute arbitrary code by instantiating certain COM objects from Wmm2fxa.dll as ActiveX controls including (1) DXImageTransform.Microsoft.MMSpecialEffect1Input, (2) DXImageTransform.Microsoft.MMSpecialEffect1Input.1, (3) DXImageTransform.Microsoft.MMSpecialEffect2Inputs, (4) DXImageTransform.Microsoft.MMSpecialEffect2Inputs.1, (5) DXImageTransform.Microsoft.MMSpecialEffectInplace1Input, and (6) DXImageTransform.Microsoft.MMSpecialEffectInplace1Input.1, which causes memory corruption during garbage collection.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:29.982-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:22.778-04:00">ACCEPTED</status_change>
            <modified comment="Fixed ste:2614: set datatype to version.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:54:00.319-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:59:40.903-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:59.840-05:00">ACCEPTED</status_change>
            <modified comment="Fixed regex in ste:2889.  Implemented by Matthew Wojcik." date="2007-03-06T18:19:00.507-05:00">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2007-03-06T18:21:07.140-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:02.627-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:46:26.872-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:01:45.966-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:56.767-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:23.277-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3841.1900" negate="false" test_ref="oval:org.mitre.oval:tst:957"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1765" version="7" class="vulnerability">
      <metadata>
        <title>Exception Handling Memory Corruption Vulnerability (2K/XP)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2218" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2218"/>
        <description>Unspecified vulnerability in Internet Explorer 6.0 on Microsoft Windows XP SP2 allows remote attackers to execute arbitrary code via "exceptional conditions" that trigger memory corruption, as demonstrated using an exception handler and nested object tags, a variant of CVE-2006-1992.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:29.820-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:22.243-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:45:56.256-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:59.643-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:46:26.187-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:01:45.348-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:56.622-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:23.098-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Win2K or XP,SP1 is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2800.1555" negate="false" test_ref="oval:org.mitre.oval:tst:802"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1763" version="6" class="vulnerability">
      <metadata>
        <title>RPC Mutual Authentication Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2380" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2380"/>
        <description>Microsoft Windows 2000 SP4 does not properly validate an RPC server during mutual authentication over SSL, which allows remote attackers to spoof an RPC server, aka the "RPC Mutual Authentication Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:29.673-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:21.799-04:00">ACCEPTED</status_change>
            <modified comment="Fixed regex in ste:2889.  Implemented by Matthew Wojcik." date="2007-03-06T18:19:00.507-05:00">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2007-03-06T18:21:10.866-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:02.445-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1763 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:05:05.126-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:01:44.529-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="the version of rpcrt4.dll is less than 5.0.2195.7085" test_ref="oval:org.mitre.oval:tst:734"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1756" version="9" class="vulnerability">
      <metadata>
        <title>ART Image Rendering Vulnerability (Win2K)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2378" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2378"/>
        <description>Buffer overflow in the ART Image Rendering component (jgdw400.dll) in Microsoft Windows XP SP1 and Sp2, Server 2003 SP1 and earlier, and Windows 98 and Me allows remote attackers to execute arbitrary code via a crafted ART image that causes heap corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:29.328-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:20.829-04:00">ACCEPTED</status_change>
            <modified comment="Fixed ste:2614: set datatype to version.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:54:00.319-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:59:44.502-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:59.278-05:00">ACCEPTED</status_change>
            <modified comment="Fixed regex in ste:2889.  Implemented by Matthew Wojcik." date="2007-03-06T18:19:00.507-05:00">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2007-03-06T18:21:10.658-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:01.964-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1756 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:05:32.443-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:01:44.157-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:51.523-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:22.931-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" test_ref="oval:org.mitre.oval:tst:2794"/>
        <criterion comment="the version of jgdw400.dll is less than 106.0.0.0" test_ref="oval:org.mitre.oval:tst:835"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1748" version="3" class="vulnerability">
      <metadata>
        <title>FPSE XSS Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft FrontPage Server Extensions 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0015" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0015"/>
        <description>Cross-site scripting (XSS) vulnerability in _vti_bin/_vti_adm/fpadmdll.dll in Microsoft FrontPage Server Extensions 2002 and SharePoint Team Services allows remote attackers to inject arbitrary web script or HTML, then leverage the attack to execute arbitrary programs or create new accounts, via the (1) operation, (2) command, and (3) name parameters.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-13T02:47:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-19T10:08:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-10T08:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1748 - Modified vulnerabilities - a lot of fixes" date="2015-07-22T13:29:00.390-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-22T13:32:13.283-04:00">INTERIM</status_change>
            <status_change date="2015-08-10T04:00:22.654-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Windows 2000, XP, or 2003 is installed">
          <criterion comment="Windows 2000 is installed" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Windows XP is installed" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="Windows Server 2003 is installed" test_ref="oval:org.mitre.oval:tst:2761"/>
        </criteria>
        <extend_definition comment="Microsoft FrontPage Server Extensions 2002 is installed" definition_ref="oval:org.mitre.oval:def:28542"/>
        <criterion comment="Fpadmdll.dll version is less than 10.0.6790.0" test_ref="oval:org.mitre.oval:tst:744"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28542" version="3" class="inventory">
      <metadata>
        <title>Microsoft FrontPage Server Extensions 2002 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft FrontPage Server Extensions 2002</product>
        </affected>
        <reference ref_id="cpe:/a:microsoft:frontpage_server_extensions:2002" source="CPE"/>
        <description>Microsoft FrontPage Server Extensions 2002 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-05T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </submitted>
            <status_change date="2015-06-10T14:07:23.441-04:00">DRAFT</status_change>
            <status_change date="2015-06-29T04:00:05.749-04:00">INTERIM</status_change>
            <status_change date="2015-07-20T04:00:09.785-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="FrontPage Server Extensions 2002 are enabled (NT, 2K, XP)" test_ref="oval:org.mitre.oval:tst:2677"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1741" version="6" class="vulnerability">
      <metadata>
        <title>RRAS Memory Corruption Vulnerability (Win2K)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2370" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2370"/>
        <description>Buffer overflow in the Routing and Remote Access service (RRAS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote unauthenticated or authenticated attackers to execute arbitrary code via certain crafted "RPC related requests," aka the "RRAS Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:28.842-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:20.005-04:00">ACCEPTED</status_change>
            <modified comment="Fixed regex in ste:2889.  Implemented by Matthew Wojcik." date="2007-03-06T18:19:00.507-05:00">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2007-03-06T18:21:15.391-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:01.686-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1741 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:06:12.762-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:01:41.863-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="the version of rasmans.dll is less than 5.0.2195.7093" test_ref="oval:org.mitre.oval:tst:747"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1740" version="8" class="vulnerability">
      <metadata>
        <title>IE5 Address Bar Spoofing Vulnerability (Win2K)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1192" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1192"/>
        <description>Microsoft Internet Explorer 5.01 through 6 allows remote attackers to conduct phishing attacks by spoofing the address bar and other parts of the trust UI via unknown methods that allow "window content to persist" after the user has navigated to another site, aka the "Address Bar Spoofing Vulnerability."  NOTE: this is a different vulnerability than CVE-2006-1626.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Modified ste:831: altered regex to match on a double zero in the minor field of the version, and also added an initial anchor.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:27:00.230-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:28:37.014-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:58.891-05:00">ACCEPTED</status_change>
            <modified comment="Fixed regex in ste:2889.  Implemented by Matthew Wojcik." date="2007-03-06T18:19:00.507-05:00">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2007-03-06T18:21:12.081-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:01.477-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:46:07.602-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:01:41.503-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:53.470-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:22.813-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="Internet Explorer 5.01 (any patch level) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:927"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3839.2200" negate="false" test_ref="oval:org.mitre.oval:tst:926"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1736" version="5" class="vulnerability">
      <metadata>
        <title>IE5.01,SP3 Security Zone Restriction Bypass Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0054" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0054"/>
        <description>Internet Explorer 5.01, 5.5, and 6 allows remote attackers to spoof a less restrictive security zone and execute arbitrary code via an HTML page containing URLs that contain hostnames that have been double hex encoded, which are decoded twice to generate a malicious hostname, aka the "URL Decoding Zone Spoofing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-03-23T08:09:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-13T12:15:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-05-04T12:33:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed test to check kb867282.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2824. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:48:00.494-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:52:25.682-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:58.661-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:47.305-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:22.708-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3015"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3528.700" negate="false" test_ref="oval:org.mitre.oval:tst:749"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1722" version="3" class="vulnerability">
      <metadata>
        <title>Uninitialized Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0944" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0944"/>
        <description>Unspecified vulnerability in the CTableCol::OnPropertyChange method in Microsoft Internet Explorer 5.01 SP4 on Windows 2000 SP4; 6 SP1 on Windows 2000 SP4; and 6 on Windows XP SP2, or Windows Server 2003 SP1 or SP2 allows remote attackers to execute arbitrary code by calling deleteCell on a named table row in a named table column, then accessing the column, which causes Internet Explorer to access previously deleted objects, aka the "Uninitialized Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2007-05-08T19:30:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-05-09T12:53:06-04:00">DRAFT</status_change>
            <status_change date="2007-05-31T15:26:34.887-04:00">INTERIM</status_change>
            <modified comment="Corrected version of ste:3224. Implemented by Jon Baker of the MITRE Corporation." date="2007-06-04T08:42:00.584-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <modified comment="Corrected criteria on 64 bit check" date="2007-06-07T08:42:00.584-04:00">
              <contributor organization="Secure Elements, Inc.">Jeff Ito</contributor>
            </modified>
            <status_change date="2007-06-22T08:57:41.090-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3877 - modified comments" date="2014-02-28T15:13:00.247-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-28T15:16:17.347-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:14.336-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="IE 5.01,SP4 on Win2k,SP4" operator="AND">
          <extend_definition comment="Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Internet Explorer 5.01, SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3850.1900" test_ref="oval:org.mitre.oval:tst:3859"/>
        </criteria>
        <criteria comment="IE 6 on Windows 2000" operator="AND">
          <extend_definition comment="Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1593" test_ref="oval:org.mitre.oval:tst:3454"/>
        </criteria>
        <criteria comment="IE 6 on Windows XP SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1593" test_ref="oval:org.mitre.oval:tst:3454"/>
        </criteria>
        <criteria comment="XP,SP1 (64-bit) and Server 2003, SP1 (IE6)" operator="AND">
          <criteria operator="OR" comment="Windows XP (64-bit,SP1) or Server 2003 (SP1) is installed">
            <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          </criteria>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2885" test_ref="oval:org.mitre.oval:tst:3810"/>
        </criteria>
        <criteria comment="XP,SP2 (64-bit) and Server 2003, SP2 (IE6)" operator="AND">
          <criteria operator="OR" comment="Windows XP (64-bit,SP2) or Server 2003 (SP1) is installed">
            <criteria operator="AND" comment="Windows XP (64-bit,SP2) is installed">
              <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
              <criterion comment="64-Bit version of Windows is installed" test_ref="oval:org.mitre.oval:tst:2744"/>
            </criteria>
            <extend_definition comment="Windows Server 2003, SP2 is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          </criteria>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.4026" test_ref="oval:org.mitre.oval:tst:3176"/>
        </criteria>
        <criteria comment="IE 7 on Windows XP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="the version of Ieapfltr.dll is less than 7.0.6000.16432" test_ref="oval:org.mitre.oval:tst:3877"/>
        </criteria>
        <criteria comment="Windows Server 2003 Service Pack 1 version" operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 (x86) SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of Ieapfltr.dll is less than 7.0.6000.16432" test_ref="oval:org.mitre.oval:tst:3877"/>
        </criteria>
        <criteria comment="Windows Server 2003 Service Pack 2 version" operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <criterion comment="the version of Ieapfltr.dll is less than 7.0.6000.16432" test_ref="oval:org.mitre.oval:tst:3877"/>
        </criteria>
        <criteria comment="IE 7 on Windows Vista" operator="AND">
          <extend_definition comment="Windows Vista is installed" definition_ref="oval:org.mitre.oval:def:228"/>
          <criterion comment="the version of mshtml.dll is less than 7.0.6000.20547" test_ref="oval:org.mitre.oval:tst:3334"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1721" version="6" class="vulnerability">
      <metadata>
        <title>GDI+ JPEG Parsing Engine Buffer Overflow (VS.NET 2003)</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Visual Studio .NET 2003</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0200" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0200"/>
        <description>Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-09-24T04:32:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-09-29T02:08:00.000-04:00">DRAFT</status_change>
            <modified date="2004-09-30T11:39:00.000-04:00" comment="changed affected platforms">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2004-10-20T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed test to check KB830348.  Added check for VS.NET Gdiplus.dll in WinSxS.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 578 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-28T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:27.749-04:00">ACCEPTED</status_change>
            <modified comment="var:228 updated: reference to windir environment variable object obj:577 replaced with obj:219, the registry object for SystemRoot.  Literal component now starts with a backslash.  Implemented by Harvey Rubinovitz." date="2007-01-05T16:46:00.401-05:00">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2007-01-05T16:52:19.546-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:57.937-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:755 - Updating criterion logic and check attributes for Gdiplus.dll related Objects." date="2013-12-30T09:14:00.018-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-30T09:17:36.748-05:00">INTERIM</status_change>
            <status_change date="2014-01-20T04:00:16.348-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Microsoft Visual Studio .NET 2003 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:756"/>
        <criterion comment="the version of Gdiplus.dll for Visual Studio .NET is less than 5.1.3102.1355" negate="false" test_ref="oval:org.mitre.oval:tst:755"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1711" version="8" class="vulnerability">
      <metadata>
        <title>IE5 HTML Parsing Vulnerability (Win2K)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1185" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1185"/>
        <description>Unspecified vulnerability in Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via certain invalid HTML that causes memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Modified ste:831: altered regex to match on a double zero in the minor field of the version, and also added an initial anchor.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:27:00.230-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:28:36.850-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:57.542-05:00">ACCEPTED</status_change>
            <modified comment="Fixed regex in ste:2889.  Implemented by Matthew Wojcik." date="2007-03-06T18:19:00.507-05:00">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2007-03-06T18:21:06.192-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:00.769-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:44:15.552-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:01:38.956-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:41.350-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:22.579-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="Internet Explorer 5.01 (any patch level) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:927"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3839.2200" negate="false" test_ref="oval:org.mitre.oval:tst:926"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:171" version="10" class="vulnerability">
      <metadata>
        <title>Window Location Information Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference ref_id="CVE-2006-3640" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3640" source="CVE"/>
        <description>Microsoft Internet Explorer 5.01 and 6 allows certain script to persist across navigations between pages, which allows remote attackers to obtain the window location of visited web pages in other domains or zones, aka "Window Location Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:28:54.442-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:35.019-04:00">ACCEPTED</status_change>
            <modified comment="Added an anchor to the regex used to check for Internet Explorer 6." date="2007-01-11T20:38:00.950-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-01-11T20:49:15.476-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:57.252-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:2185 - Anchored regular expression" date="2011-02-22T12:51:00.261-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:52:31.139-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:00:48.528-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:38.104-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:22.410-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:136 - modified comments" date="2014-02-28T15:13:00.247-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-28T15:16:21.215-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:14.045-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:171 - Addressed validation errors and duplicate extended definitions" date="2015-07-13T20:21:00.869-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:25:25.529-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:01:03.147-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Server 2003-Gold">
          <extend_definition comment="Microsoft Windows Server 2003 (x86) Gold is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.554" test_ref="oval:org.mitre.oval:tst:136"/>
        </criteria>
        <criteria comment="XP,SP1 (64-bit) and Server 2003, SP1">
          <criteria operator="OR" comment="Windows XP (64-bit,SP1) or Server 2003 (SP1) is installed">
            <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2759" test_ref="oval:org.mitre.oval:tst:175"/>
        </criteria>
        <criteria comment="IE 6 on Windows XP,SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.2963" test_ref="oval:org.mitre.oval:tst:95"/>
        </criteria>
        <criteria comment="IE 6 on Windows 2000 or XP,SP1 (32-bit)">
          <criteria operator="OR" comment="Win2K,SP4 or XP,SP1 (32-bit) is installed">
            <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
            <extend_definition comment="Microsoft Windows XP SP1 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1561" test_ref="oval:org.mitre.oval:tst:56"/>
        </criteria>
        <criteria comment="IE 5.01,SP4 on Win2k,SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3842.3000" test_ref="oval:org.mitre.oval:tst:106"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1706" version="3" class="vulnerability">
      <metadata>
        <title>Network News Transfer Protocol Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Outlook Express</product>
        </affected>
        <reference ref_id="CVE-2007-3897" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3897" source="CVE"/>
        <description>Heap-based buffer overflow in Microsoft Outlook Express 6 and earlier, and Windows Mail for Vista, allows remote Network News Transfer Protocol (NNTP) servers to execute arbitrary code via long NNTP responses that trigger memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-10-09T03:28:00.000-04:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-10-11T09:42:32.651-04:00">DRAFT</status_change>
            <modified comment="Fixed typo in criteria block (S03,SP1 was used where S03,SP2 was intended)." date="2007-10-15T15:41:00.197-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-11-02T07:17:29.726-04:00">INTERIM</status_change>
            <status_change date="2007-11-19T04:00:33.250-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1706 - Correcting incorrect references to 64-bit Itanium XP." date="2012-08-23T17:47:00.168-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-08-23T17:52:51.186-04:00">INTERIM</status_change>
            <status_change date="2012-09-10T04:00:40.123-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Microsoft Outlook Express 5.5 SP2 on Win 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Outlook Express 5.5 SP2 is installed." definition_ref="oval:org.mitre.oval:def:504"/>
          <criterion comment="the version of inetcomm.dll is less than 5.50.4980.1600" test_ref="oval:org.mitre.oval:tst:3808"/>
        </criteria>
        <criteria operator="AND" comment="Outlook Express 6 SP1 on Win 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Outlook Express 6 SP1 is installed." definition_ref="oval:org.mitre.oval:def:488"/>
          <criterion comment="the version of inetcomm.dll is less than 6.0.2800.1914" test_ref="oval:org.mitre.oval:tst:4113"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Outlook Express 6 on Win XP SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Microsoft Outlook Express 6.0 for Windows XP/2003 is installed" definition_ref="oval:org.mitre.oval:def:208"/>
          <criterion comment="the version of inetcomm.dll is less than 6.0.2900.3198" test_ref="oval:org.mitre.oval:tst:4195"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Outlook Express 6 on Win 2k3 SP1">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <extend_definition comment="Microsoft Outlook Express 6.0 for Windows XP/2003 is installed" definition_ref="oval:org.mitre.oval:def:208"/>
          <criterion comment="the version of inetcomm.dll is less than 6.0.3790.2992" test_ref="oval:org.mitre.oval:tst:3865"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Outlook Express 6 on Win 2k3 SP2">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <extend_definition comment="Microsoft Outlook Express 6.0 for Windows XP/2003 is installed" definition_ref="oval:org.mitre.oval:def:208"/>
          <criterion comment="the version of inetcomm.dll is less than 6.0.3790.4133" test_ref="oval:org.mitre.oval:tst:4531"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Outlook Express 6 on Win XP SP2 (64-bit)">
          <extend_definition comment="Microsoft Outlook Express 6.0 for Windows XP/2003 is installed" definition_ref="oval:org.mitre.oval:def:208"/>
          <criterion comment="the version of inetcomm.dll is less than 6.0.3790.4133" test_ref="oval:org.mitre.oval:tst:4531"/>
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
        </criteria>
        <criteria operator="AND" comment="Windows Mail on Windows Vista">
          <criteria operator="OR" comment="Windows Vista 32-bit or 64-bit">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <extend_definition comment="Microsoft Windows Mail is installed" definition_ref="oval:org.mitre.oval:def:2058"/>
          <criterion comment="the version of inetcomm.dll is less than 6.0.6000.16545" test_ref="oval:org.mitre.oval:tst:4330"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2058" version="5" class="inventory">
      <metadata>
        <title>Microsoft Windows Mail is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Windows Mail</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:windows_mail"/>
        <description>Microsoft Windows Mail is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2007-06-13T12:32:06.000-04:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-06-13T15:20:00.000-04:00">DRAFT</status_change>
            <modified comment="Corrected regex in ste:3814 to account for both commas and dots, also anchored the boundaries." date="2007-06-15T13:10:00.106-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-07-03T14:05:59.294-04:00">INTERIM</status_change>
            <status_change date="2007-07-18T15:57:52.876-04:00">ACCEPTED</status_change>
            <modified comment="Corrected comment for oval:org.mitre.oval:tst:3506 and updated ste:3814 to match with newer versions of Windows Mail 6.0." date="2010-05-12T11:21:00.138-04:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2010-05-12T11:23:48.997-04:00">INTERIM</status_change>
            <modified comment="Added new test to check for Windows Mail 6.1" date="2010-05-12T11:57:00.591-04:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2010-05-31T04:00:05.436-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:06.275-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:06.275-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:02:59.237-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Windows Mail version 6.0" test_ref="oval:org.mitre.oval:tst:3506"/>
        <criterion comment="Windows Mail version 6.1" test_ref="oval:org.mitre.oval:tst:11318"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1702" version="9" class="vulnerability">
      <metadata>
        <title>IE6 DHTML Method Call Memory Corruption (Win2K/XP,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1359" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1359"/>
        <description>Microsoft Internet Explorer 6 and 7 Beta 2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a certain createTextRange call on a checkbox object, which results in a dereference of an invalid table pointer.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added an anchor to the regex used to check for Internet Explorer 6." date="2007-01-11T20:38:00.950-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-01-11T20:49:16.639-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:56.920-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:2185 - Anchored regular expression" date="2011-02-22T12:51:00.261-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:52:27.983-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:00:48.155-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:44:03.331-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:01:38.080-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:39.129-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:22.278-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Win2K or XP,SP1 is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="Internet Explorer 6 (any patch level) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2333"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2800.1543" negate="false" test_ref="oval:org.mitre.oval:tst:2332"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:17" version="3" class="vulnerability">
      <metadata>
        <title>IE GetObject Security Bypass</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0023" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0023"/>
        <description>Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to read arbitrary files via malformed requests to the GetObject function, which bypass some of GetObject's security checks.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T05:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="changed IE test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:43.577-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:22.161-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the version of mshtml.dll is less than 6.0.2713.1100" negate="false" test_ref="oval:org.mitre.oval:tst:3091"/>
        <criterion comment="the patch q316059 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3121"/>
        <criterion comment="the patch q319282 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3120"/>
        <criterion comment="the patch q321232 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3119"/>
        <criterion comment="the patch q323759 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3118"/>
        <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
        <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
        <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16925" version="4" class="vulnerability">
      <metadata>
        <title>Vulnerability in the Management Pack for Oracle GoldenGate Server. Supported versions that are affected are 11.1.1.1.0.
		Vulnerability in the Oracle GoldenGate Veridata component of Oracle Fusion Middleware (subcomponent: Server). The supported version that is affected is 3.0.0.11.0. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP. Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle GoldenGate Veridata</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Oracle GoldenGate Director</product>
          <product>Oracle GoldenGate Veridata</product>
        </affected>
        <reference ref_id="CVE-2012-0022" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0022" source="CVE"/>
        <description>Apache Tomcat 5.5.x before 5.5.35, 6.x before 6.0.34, and 7.x before 7.0.23 uses an inefficient approach for handling parameters, which allows remote attackers to cause a denial of service (CPU consumption) via a request that contains many parameters and parameter values, a different vulnerability than CVE-2011-4858.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-04-29T10:26:26.748+04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2013-06-19T16:06:43.613-04:00">DRAFT</status_change>
            <status_change date="2013-07-08T04:02:15.887-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:00:59.180-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Check if version of Oracle GoldenGate Director is 11.1.1.1.0" test_ref="oval:org.mitre.oval:tst:81231"/>
        <criterion comment="Check if version for Oracle GoldenGate Veridata is 3.0.0.11.0" test_ref="oval:org.mitre.oval:tst:80940"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1687" version="3" class="vulnerability">
      <metadata>
        <title>Mozilla Crashes with Evidence of Memory Corruption (moz-grid)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1738" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1738"/>
        <description>Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) by changing the (1) -moz-grid and (2) -moz-grid-group display styles.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-07T09:05:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:26.582-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:1133" date="2007-02-26T08:08:00.208-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-26T08:09:12.310-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:1135" date="2007-02-26T08:21:00.993-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:1136" date="2007-02-26T08:24:00.848-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:1138" date="2007-02-26T08:25:00.405-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:2283" date="2007-02-26T08:29:00.407-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:2284" date="2007-02-26T08:30:00.724-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:59.709-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:881" date="2007-04-23T12:05:00.811-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:12:49.901-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:882" date="2007-04-23T12:05:00.939-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in obj:883" date="2007-04-23T12:05:00.804-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in obj:1385" date="2007-04-23T12:05:00.430-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:10:57.510-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1268"/>
          <criterion comment="Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1267"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Thunderbird version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1266"/>
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1265"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.12 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1264"/>
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1263"/>
        </criteria>
        <criteria operator="AND" comment="A pre-release of SeaMonkey 1.0 is installed">
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2439"/>
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2438"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1682" version="5" class="vulnerability">
      <metadata>
        <title>Microsoft Outlook Express 6,SP1 WAB Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Outlook Express</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0014" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0014"/>
        <description>Buffer overflow in Microsoft Outlook Express 5.5 and 6 allows remote attackers to execute arbitrary code via a crafted Windows Address Book (WAB) file containing "certain Unicode strings" and modified length values.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added Microsoft Windows XP to the affected platforms. Implemented by Jon Baker of The MITRE Corporation." date="2007-02-12T20:14:00.684-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-02-12T20:15:48.708-05:00">INTERIM</status_change>
            <modified comment="Fixed regex in ste:2889.  Implemented by Matthew Wojcik." date="2007-03-06T18:19:00.507-05:00">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:59.406-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:27.977-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:01:35.093-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Windows XP,SP1 32-bit or Win2K,SP4 is installed">
          <criteria operator="AND" comment="Windows XP,SP1 32-bit is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
            <criterion comment="64-Bit version of Windows is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2747"/>
          </criteria>
          <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
            <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
            <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
          </criteria>
        </criteria>
        <criterion comment="Microsoft Outlook Express 6 SP1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1355"/>
        <criterion comment="the version of inetcomm.dll is less than 6.0.2800.1807" negate="false" test_ref="oval:org.mitre.oval:tst:779"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1678" version="8" class="vulnerability">
      <metadata>
        <title>IE 5.01 DHTML Method Call Memory Corruption</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1359" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1359"/>
        <description>Microsoft Internet Explorer 6 and 7 Beta 2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a certain createTextRange call on a checkbox object, which results in a dereference of an invalid table pointer.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Modified ste:831: altered regex to match on a double zero in the minor field of the version, and also added an initial anchor.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:27:00.230-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:28:36.674-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:56.273-05:00">ACCEPTED</status_change>
            <modified comment="Fixed regex in ste:2889.  Implemented by Matthew Wojcik." date="2007-03-06T18:19:00.507-05:00">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2007-03-06T18:21:07.557-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:16:58.992-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:46:21.281-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:01:34.247-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:55.642-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:21.911-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="Internet Explorer 5.01 (any patch level) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:927"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3839.2200" negate="false" test_ref="oval:org.mitre.oval:tst:926"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1677" version="4" class="vulnerability">
      <metadata>
        <title>IE6 HTML Parsing Vulnerability (Server 2003,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1185" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1185"/>
        <description>Unspecified vulnerability in Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via certain invalid HTML that causes memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:46:22.830-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:01:33.929-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.2666" negate="false" test_ref="oval:org.mitre.oval:tst:1126"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1673" class="vulnerability" version="1">
      <metadata>
        <title>CSS Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0943" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0943"/>
        <description>Unspecified vulnerability in Internet Explorer 5.01 and 6 SP1 allows remote attackers to execute arbitrary code via crafted Cascading Style Sheets (CSS) strings that trigger memory corruption during parsing, related to use of out-of-bounds pointers.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-15T09:28:35">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-08-15T15:55:13.423-04:00">DRAFT</status_change>
            <modified comment="Added version datatype to file_state version element. Altered oval:org.mitre.oval:ste:3811" date="2007-08-23T14:13:00.397-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-09-10T14:45:25.914-04:00">INTERIM</status_change>
            <status_change date="2007-09-27T08:57:41.035-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="IE 5.01,SP4 on Win2k,SP4" operator="AND">
          <extend_definition comment="Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Internet Explorer 5.01,SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="the version of Mshtml.dll is less than 5.0.3854.1200" test_ref="oval:org.mitre.oval:tst:4193"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16725" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in Sun VirtualBox 3.0.0 and 3.0.2</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>VirtualBox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2714" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2714"/>
        <description>Unspecified vulnerability in Sun VirtualBox 3.0.0 and 3.0.2 allows guest OS users to cause a denial of service (host OS reboot) via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-04-25T16:31:26.748+04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2013-05-15T15:01:29.404-04:00">DRAFT</status_change>
            <status_change date="2013-06-03T04:03:31.002-04:00">INTERIM</status_change>
            <status_change date="2013-06-24T04:00:13.958-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:16725 - modificated vulnerabilities for VirtualBox" date="2013-12-05T10:43:00.197-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-05T10:45:12.580-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:00:32.540-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="VirtualBox is installed" definition_ref="oval:org.mitre.oval:def:11581"/>
        <criterion comment="Check if Sun xVM VirtualBox is installed" test_ref="oval:org.mitre.oval:tst:41938"/>
        <criterion comment="Check if Sun xVM VirtualBox version is greater than or equals to 3.0.0" test_ref="oval:org.mitre.oval:tst:88496"/>
        <criterion comment="Check if Sun xVM VirtualBox version is less than or equals to 3.0.2" test_ref="oval:org.mitre.oval:tst:88902"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16722" version="7" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization 4.1 allows local users to affect confidentiality and integrity via unknown vectors related to Shared Folders</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>VirtualBox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2012-0111" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0111"/>
        <description>Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization 4.1 allows local users to affect confidentiality and integrity via unknown vectors related to Shared Folders.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-04-26T14:33:26.748+04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2013-05-15T15:01:31.559-04:00">DRAFT</status_change>
            <status_change date="2013-06-03T04:03:30.696-04:00">INTERIM</status_change>
            <status_change date="2013-06-24T04:00:13.205-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:16722 - modificated vulnerabilities for VirtualBox" date="2013-12-05T10:43:00.197-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-05T10:45:11.481-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:00:32.456-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:16722 - New vulnerability(CVE-2013-5892) added and modified existing criteria" date="2014-01-30T14:45:00.034-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-30T14:49:21.565-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:11.454-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="VirtualBox is installed" definition_ref="oval:org.mitre.oval:def:11581"/>
        <criterion comment="Check if Oracle VM VirtualBox is installed" test_ref="oval:org.mitre.oval:tst:42006"/>
        <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.1.0" test_ref="oval:org.mitre.oval:tst:88836"/>
        <criterion comment="Check if Oracle VM VirtualBox version is less than 4.2.0" test_ref="oval:org.mitre.oval:tst:99346"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1670" version="7" class="vulnerability">
      <metadata>
        <title>CAPICOM.Certificates Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Capicom</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0940" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0940"/>
        <description>Unspecified vulnerability in the Cryptographic API Component Object Model Certificates ActiveX control (CAPICOM.dll) in Microsoft CAPICOM and BizTalk Server 2004 SP1 and SP2 allows remote attackers to execute arbitrary code via unspecified vectors, aka the "CAPICOM.Certificates Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2007-05-08T19:30:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-05-09T12:53:06-04:00">DRAFT</status_change>
            <modified comment="Removed unneeded criteria. This definition still needs to be updated to check for the vulnerable capicom.dll in locations other than the system root." date="2007-05-23T13:58:00.503-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="added unknown_test as a place holder until oval can support the test that is needed to check that the currently registered version of capicom.dll is not vulnerable." date="2007-06-01T10:17:00.628-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-06-20T07:39:21.924-04:00">INTERIM</status_change>
            <status_change date="2007-07-10T21:08:49.262-04:00">ACCEPTED</status_change>
            <modified comment="References registry entries that will remove false positives in tests." date="2008-03-26T13:25:00.871-04:00">
              <contributor organization="GFI Software">Clifford Farrugia</contributor>
            </modified>
            <status_change date="2008-03-26T13:27:19.903-04:00">INTERIM</status_change>
            <modified comment="Changed criteria operator from OR to AND" date="2008-03-27T08:39:00.510-04:00">
              <contributor organization="GFI Software">Clifford Farrugia</contributor>
            </modified>
            <modified comment="Changed wording for criterion comment and added a negate flag." date="2008-04-03T08:55:00.399-04:00">
              <contributor organization="GFI Software">Clifford Farrugia</contributor>
            </modified>
            <status_change date="2008-04-21T04:00:13.519-04:00">ACCEPTED</status_change>
            <modified comment="Added platforms based on MS Bulletin information." date="2008-06-27T09:26:00.595-04:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2008-06-27T09:44:19.609-04:00">INTERIM</status_change>
            <status_change date="2008-07-14T04:00:18.128-04:00">ACCEPTED</status_change>
            <modified comment="Changed registry key check to include beginning anchor to optimize search by limiting the scope of the search." date="2010-01-22T11:54:00.769-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2010-01-22T11:57:05.984-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:02.203-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1670 - Modified vulnerabilities - a lot of fixes" date="2015-07-22T13:29:00.390-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-22T13:32:16.975-04:00">INTERIM</status_change>
            <status_change date="2015-08-10T04:00:20.949-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Capicom is installed" definition_ref="oval:org.mitre.oval:def:29097"/>
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criteria operator="AND">
          <criterion comment="capicom is installed" test_ref="oval:org.mitre.oval:tst:7951"/>
          <criterion negate="true" comment="the version of capicom is 2.1.0.2 or greater" test_ref="oval:org.mitre.oval:tst:7495"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29097" version="3" class="inventory">
      <metadata>
        <title>Microsoft Capicom is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Capicom</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:capicom"/>
        <description>Microsoft Capicom is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-05T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </submitted>
            <status_change date="2015-06-10T14:07:21.452-04:00">DRAFT</status_change>
            <status_change date="2015-06-29T04:00:09.696-04:00">INTERIM</status_change>
            <status_change date="2015-07-20T04:00:13.805-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="capicom is installed" test_ref="oval:org.mitre.oval:tst:7951"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16681" version="8" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the Oracle VM Virtual Box component in Oracle Virtualization 3.2, 4.0, and 4.1</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>VirtualBox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2012-3221" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3221"/>
        <description>Unspecified vulnerability in the Oracle VM Virtual Box component in Oracle Virtualization 3.2, 4.0, and 4.1 allows local users to affect availability via unknown vectors related to VirtualBox Core.  NOTE: The previous information was obtained from the October 2012 CPU. Oracle has not commented on claims from another vendor that this issue is related to "incorrect interrupt handling."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-04-26T14:33:26.748+04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2013-05-15T15:01:32.442-04:00">DRAFT</status_change>
            <status_change date="2013-06-03T04:03:25.640-04:00">INTERIM</status_change>
            <status_change date="2013-06-24T04:00:11.296-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15297 - modificated vulnerabilities for VirtualBox" date="2013-12-05T10:43:00.197-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-05T10:45:12.353-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:00:32.336-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:16681 - New vulnerability(CVE-2013-5892) added and modified existing criteria" date="2014-01-30T14:45:00.034-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-30T14:49:21.841-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:11.249-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="VirtualBox is installed" definition_ref="oval:org.mitre.oval:def:11581"/>
        <criterion comment="Check if Oracle VM VirtualBox is installed" test_ref="oval:org.mitre.oval:tst:42006"/>
        <criteria operator="OR" comment="Check versions of VirtualBox">
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 3.2.0" test_ref="oval:org.mitre.oval:tst:88842"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than or equals to 4.0.6" test_ref="oval:org.mitre.oval:tst:88945"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version  is greater than or equals to 4.0.8" test_ref="oval:org.mitre.oval:tst:88912"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than 4.2.0" test_ref="oval:org.mitre.oval:tst:99346"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1667" version="3" class="vulnerability">
      <metadata>
        <title>Mozilla Crashes with Evidence of Memory Corruption (CSS BO)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1739" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1739"/>
        <description>The CSS border-rendering code in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain Cascading Style Sheets (CSS) that causes an out-of-bounds array write and buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-07T09:05:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:25.785-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:1133" date="2007-02-26T08:08:00.208-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-26T08:09:14.769-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:1135" date="2007-02-26T08:21:00.993-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:1136" date="2007-02-26T08:24:00.848-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:1138" date="2007-02-26T08:25:00.405-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:2283" date="2007-02-26T08:29:00.407-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:2284" date="2007-02-26T08:30:00.724-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:58.683-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:881" date="2007-04-23T12:05:00.811-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:12:52.800-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:882" date="2007-04-23T12:05:00.939-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in obj:883" date="2007-04-23T12:05:00.804-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in obj:1385" date="2007-04-23T12:05:00.430-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:10:57.043-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1268"/>
          <criterion comment="Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1267"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Thunderbird version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1266"/>
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1265"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.12 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1264"/>
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1263"/>
        </criteria>
        <criteria operator="AND" comment="A pre-release of SeaMonkey 1.0 is installed">
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2439"/>
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2438"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1665" version="7" class="vulnerability">
      <metadata>
        <title>MHT Memory Corruption Vulnerability (2K/XP)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2385" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2385"/>
        <description>Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows user-assisted remote attackers to execute arbitrary code via a crafted web page that triggers memory corruption when it is saved as a multipart HTML (.mht) file.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:25.404-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:14.406-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:46:04.261-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:55.835-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:46:28.728-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:01:32.314-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:57.135-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:21.567-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Win2K or XP,SP1 is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2800.1555" negate="false" test_ref="oval:org.mitre.oval:tst:802"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1661" version="4" class="vulnerability">
      <metadata>
        <title>Windows Media Player 9 Bitmap Remote Code Execution</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Windows Media Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0006" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0006"/>
        <description>Heap-based buffer overflow in the bitmap processing routine in Microsoft Windows Media Player 7.1 on Windows 2000 SP4, Media Player 9 on Windows 2000 SP4 and XP SP1, and Media Player 10 on XP SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted bitmap (.BMP) file that specifies a size of 0 but contains additional data.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-17T07:36:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-22T08:27:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Modified ste:705: altered regex to match on a double zero in the minor field of the version, and also added an initial anchor.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:23:00.679-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:25:34.781-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:55.645-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:705 - added trailing $ to regexs" date="2011-10-31T09:26:00.646-04:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2011-10-31T09:31:24.308-04:00">INTERIM</status_change>
            <status_change date="2011-11-21T04:13:07.300-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Media Player 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:786"/>
        <criterion comment="the version of Wmp.dll is less than 9.0.0.3344" negate="false" test_ref="oval:org.mitre.oval:tst:785"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16445" version="5" class="vulnerability">
      <metadata>
        <title>SharePoint Directory Traversal Vulnerability - MS13-024</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft SharePoint Foundation 2010</product>
          <product>Microsoft SharePoint Server 2010</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-0084" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0084"/>
        <description>Directory traversal vulnerability in Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allows remote attackers to bypass intended read restrictions for content, and hijack user accounts, via a crafted URL, aka "SharePoint Directory Traversal Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-03-14T12:59:10">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-03-18T14:52:41.326-04:00">DRAFT</status_change>
            <status_change date="2013-04-08T04:00:29.945-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:17:05.574-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:1390 - November 2014 bulletins." date="2014-11-17T17:25:00.386-05:00">
              <contributor organization="SecPod Technologies">Kumarswamy S</contributor>
            </modified>
            <status_change date="2014-11-17T17:29:49.054-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:12.814-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if the version of Onfda.dll is less than 14.0.6134.5000" test_ref="oval:org.mitre.oval:tst:80956"/>
        <extend_definition comment="Microsoft SharePoint Foundation 2010 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:15661"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1644" version="5" class="vulnerability" deprecated="true">
      <metadata>
        <title>DEPRECATED: Microsoft JScript Memory Corruption Vulnerability (Win2K)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1313" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1313"/>
        <description>Microsoft JScript 5.1, 5.5, and 5.6 on Windows 2000 SP4, and 5.6 on Windows XP, Server 2003, Windows 98 and Windows Me, will "release objects early" in certain cases, which results in memory corruption and allows remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:24.831-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:13.461-04:00">ACCEPTED</status_change>
            <modified comment="Fixed regex in ste:2889.  Implemented by Matthew Wojcik." date="2007-03-06T18:19:00.507-05:00">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2007-03-06T18:21:06.606-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:16:57.859-04:00">ACCEPTED</status_change>
            <modified comment="Use def:1067 instead, which covers all appropriate versions of the DLL" date="2011-01-20T10:31:19.840-05:00">
              <contributor organization="The MITRE Corporation">Nate Przybyszewski</contributor>
            </modified>
            <status_change date="2011-01-20T10:31:19.840-05:00">DEPRECATED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="the version of Jscript.dll is less than 5.1.0.12512" negate="false" test_ref="oval:org.mitre.oval:tst:792"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1643" version="5" class="vulnerability">
      <metadata>
        <title>Win32 API Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2219" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2219"/>
        <description>Unspecified vulnerability in the Win32 API on Microsoft Windows 2000, XP SP2, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via certain parameters to an unspecified function.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-06-12T03:29:54.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-06-12T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-06-29T09:41:58.776-04:00">INTERIM</status_change>
            <status_change date="2007-07-16T09:55:09.144-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:3731 - Corrected trailing dot in version" date="2011-04-19T14:59:00.980-04:00">
              <contributor organization="The MITRE Corporation">Dan Haynes</contributor>
            </modified>
            <status_change date="2011-04-19T14:59:41.119-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:18.017-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1643 - Correcting incorrect references to 64-bit Itanium XP." date="2012-08-23T17:47:00.168-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-08-23T17:52:56.645-04:00">INTERIM</status_change>
            <status_change date="2012-09-10T04:00:39.549-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win2K,SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="The version of Kernel32.dll is less than 5.0.2195.7135." test_ref="oval:org.mitre.oval:tst:3738"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="The version of Kernel32.dll is less than 5.1.2600.3119." test_ref="oval:org.mitre.oval:tst:3304"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP1 (64-bit)">
          <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="The version of Kernel32.dll is less than 5.2.3790.2919." test_ref="oval:org.mitre.oval:tst:3630"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP2 (64-bit)">
          <criterion comment="The version of Kernel32.dll is less than 5.2.3790.4062." test_ref="oval:org.mitre.oval:tst:3786"/>
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
        </criteria>
        <criteria operator="AND" comment="S03,SP1">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="The version of Kernel32.dll is less than 5.2.3790.2919." test_ref="oval:org.mitre.oval:tst:3630"/>
        </criteria>
        <criteria operator="AND" comment="S03,SP2">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <criterion comment="The version of Kernel32.dll is less than 5.2.3790.4062." test_ref="oval:org.mitre.oval:tst:3786"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1642" version="9" class="vulnerability">
      <metadata>
        <title>IE6 HTA Execution Vulnerability (Win2K/XP,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1388" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1388"/>
        <description>Unspecified vulnerability in Microsoft Internet Explorer 6.0 allows remote attackers to execute HTA files via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added an anchor to the regex used to check for Internet Explorer 6." date="2007-01-11T20:38:00.950-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-01-11T20:49:13.899-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:55.013-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:2185 - Anchored regular expression" date="2011-02-22T12:51:00.261-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:52:32.337-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:00:47.744-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:46:46.670-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:01:28.784-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:59.909-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:21.410-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Win2K or XP,SP1 is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="Internet Explorer 6 (any patch level) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2333"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2800.1543" negate="false" test_ref="oval:org.mitre.oval:tst:2332"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16414" version="5" class="vulnerability">
      <metadata>
        <title>Buffer Overflow Vulnerability - MS13-024</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft SharePoint Foundation 2010</product>
          <product>Microsoft SharePoint Server 2010</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-0085" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0085"/>
        <description>Buffer overflow in Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allows remote attackers to cause a denial of service (W3WP process crash and site outage) via a crafted URL, aka "Buffer Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-03-14T12:59:10">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-03-18T14:52:41.572-04:00">DRAFT</status_change>
            <status_change date="2013-04-08T04:00:28.554-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:17:02.615-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:1390 - November 2014 bulletins." date="2014-11-17T17:25:00.386-05:00">
              <contributor organization="SecPod Technologies">Kumarswamy S</contributor>
            </modified>
            <status_change date="2014-11-17T17:29:48.452-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:12.526-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if the version of Onfda.dll is less than 14.0.6134.5000" test_ref="oval:org.mitre.oval:tst:80956"/>
        <extend_definition comment="Microsoft SharePoint Foundation 2010 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:15661"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15661" version="7" class="inventory">
      <metadata>
        <title>Microsoft SharePoint Foundation 2010 Service Pack 1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8</platform>
          <product>Microsoft SharePoint Foundation 2010</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:sharepoint_foundation:2010:sp1"/>
        <description>Microsoft SharePoint Foundation 2010 SP1 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2012-07-16T12:35:55">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-07-19T12:32:12.759-04:00">DRAFT</status_change>
            <status_change date="2012-08-06T04:00:14.532-04:00">INTERIM</status_change>
            <status_change date="2012-08-27T04:00:33.335-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:15661 - Microsoft Bulletins: MS13-024 and MS13-025 (March 2013)" date="2013-03-18T14:50:00.119-04:00">
              <contributor organization="SecPod Technologies">Bhavya K</contributor>
            </modified>
            <status_change date="2013-03-18T14:53:12.547-04:00">INTERIM</status_change>
            <status_change date="2013-04-08T04:00:12.383-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:24020 - Symbol \ (backslash) is not needed because symbol _ (underscore) isn't a metacharacter." date="2013-08-29T09:21:00.244-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-29T09:22:48.716-04:00">INTERIM</status_change>
            <status_change date="2013-09-16T04:00:21.018-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft SharePoint Foundation 2010 is installed" definition_ref="oval:org.mitre.oval:def:12224"/>
        <criterion comment="Check if Microsoft SharePoint Foundation 2010 Service Pack 1 is installed" test_ref="oval:org.mitre.oval:tst:79390"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1639" version="3" class="vulnerability">
      <metadata>
        <title>Kernel Local Elevation of Privilege Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1206" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1206"/>
        <description>The Virtual DOS Machine (VDM) in the Windows Kernel in Microsoft Windows NT 4.0; 2000 SP4; XP SP2; Server 2003, 2003 SP1, and 2003 SP2; and Windows Vista before June 2006; uses insecure permissions (PAGE_READWRITE) for a physical memory view, which allows local users to gain privileges by modifying the "zero page" during a race condition before the view is unmapped.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-04-10T16:31:02">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-04-10T16:31:02.000-05:00">DRAFT</status_change>
            <status_change date="2007-04-25T19:52:18.189-04:00">INTERIM</status_change>
            <modified comment="Edited tst:3662: Replaced reference to ste:2996 with ste:2976 instead; ste:2976 is the correct file version for Windows Server 2003 SP1 for CVE-2007-1206." date="2007-04-26T10:33:00.393-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <modified comment="Edited tst: 3979: Replaced reference to ste:2996 with ste:3801 instead; ste:3801 is the correct file version for Windows Server 2003 SP2 for CVE-2007-1206." date="2007-04-26T10:37:00.852-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-05-23T15:05:31.072-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1639 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:06:28.726-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:17.585-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="The version of Ntoskrnl.exe is less than 5.0.2195.7133." test_ref="oval:org.mitre.oval:tst:3492"/>
        </criteria>
        <criteria operator="AND" comment="Windows XP SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="The version of Ntoskrnl.exe is less than 5.1.2600.3093." test_ref="oval:org.mitre.oval:tst:3351"/>
        </criteria>
        <criteria operator="AND" comment="Windows Server 2003 Gold version">
          <extend_definition comment="Microsoft Windows Server 2003 is installed" definition_ref="oval:org.mitre.oval:def:128"/>
          <criterion comment="The version of Ntoskrnl.exe is less than 5.2.3790.652." test_ref="oval:org.mitre.oval:tst:3861"/>
        </criteria>
        <criteria operator="AND" comment="Windows Server 2003 Service Pack 1 version">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="The version of Ntoskrnl.exe is less than 5.2.3790.2894." test_ref="oval:org.mitre.oval:tst:3662"/>
        </criteria>
        <criteria operator="AND" comment="Windows Server 2003 Service Pack 2 version">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <criterion comment="The version of Ntoskrnl.exe is less than 5.2.3790.4035." test_ref="oval:org.mitre.oval:tst:3979"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1638" version="4" class="vulnerability">
      <metadata>
        <title>Remote Code Execution Vulnerability in IE5.01</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0020" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0020"/>
        <description>An unspecified Microsoft WMF parsing application, as used in Internet Explorer 5.01 SP4 on Windows 2000 SP4, and 5.5 SP2 on Windows Millennium, and possibly other versions, allows attackers to cause a denial of service (crash) and possibly execute code via a crafted WMF file with a manipulated WMF header size, possibly involving an integer overflow, a different vulnerability than CVE-2005-4560, and aka "WMF Image Parsing Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-17T07:36:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-22T08:27:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed ste:2614: set datatype to version.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:54:00.319-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:59:41.745-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:54.796-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:47.367-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:21.305-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3837.1200" negate="false" test_ref="oval:org.mitre.oval:tst:793"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1635" version="1" class="vulnerability">
      <metadata>
        <title>Excel Viewer 2003 Remote Code Execution via Malformed File Format</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Office</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0028" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0028"/>
        <description>Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via a BIFF parsing format file containing malformed BOOLERR records that lead to memory corruption, probably involving invalid pointers.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-15T10:53:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-15T07:17:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Xlview.exe is installed with a version less than 11.0.8012.0" negate="false" test_ref="oval:org.mitre.oval:tst:881"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1630" version="1" class="vulnerability">
      <metadata>
        <title>Excel Viewer 2003 Remote Code Execution via Malformed Graphic</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Office</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0030" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0030"/>
        <description>Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed graphic, which leads to memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-15T10:53:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-15T07:17:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Xlview.exe is installed with a version less than 11.0.8012.0" negate="false" test_ref="oval:org.mitre.oval:tst:881"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16235" version="8" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the Oracle VM VirtualBox  4.1 component</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>VirtualBox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2012-0105" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0105"/>
        <description>Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization 4.1 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Windows Guest Additions.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-04-26T14:33:26.748+04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2013-05-15T15:01:31.349-04:00">DRAFT</status_change>
            <status_change date="2013-06-03T04:02:50.801-04:00">INTERIM</status_change>
            <status_change date="2013-06-24T04:00:07.978-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15297 - modificated vulnerabilities for VirtualBox" date="2013-12-05T10:43:00.197-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-05T10:45:12.004-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:00:32.074-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:16235 - New vulnerability(CVE-2013-5892) added and modified existing criteria" date="2014-01-30T14:45:00.034-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-30T14:49:21.457-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:11.043-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="VirtualBox is installed" definition_ref="oval:org.mitre.oval:def:11581"/>
        <criterion comment="Check if Oracle VM VirtualBox is installed" test_ref="oval:org.mitre.oval:tst:42006"/>
        <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.1.0" test_ref="oval:org.mitre.oval:tst:88836"/>
        <criterion comment="Check if Oracle VM VirtualBox version is less than 4.2.0" test_ref="oval:org.mitre.oval:tst:99346"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1621" version="7" class="vulnerability">
      <metadata>
        <title>HTML Decoding Memory Corruption Vulnerability (2K/XP)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2382" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2382"/>
        <description>Heap-based buffer overflow in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remote attackers to execute arbitrary code via crafted UTF-8 encoded HTML that results in size discrepancies during conversion to Unicode, aka "HTML Decoding Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:24.300-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:12.496-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:46:04.880-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:54.342-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:50.993-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:01:27.807-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:48.794-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:21.135-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Win2K or XP,SP1 is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2800.1555" negate="false" test_ref="oval:org.mitre.oval:tst:802"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:162" class="vulnerability" version="1">
      <metadata>
        <title>Interactive Training Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Interactive Training</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3448" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3448"/>
        <description>Buffer overflow in the Step-by-Step Interactive Training in Microsoft Windows 2000 SP4, XP SP2 and Professional, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a long Syllabus string in crafted bookmark link files (cbo, cbl, or .cbm), a different issue than CVE-2005-1212.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-02-14T09:49:32">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-02-16T21:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:16:57.406-04:00">INTERIM</status_change>
            <status_change date="2007-04-10T13:44:20.985-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR">
          <extend_definition comment="Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
        </criteria>
        <criterion comment="the version of Orun32.exe is less than 3.5.0.118" test_ref="oval:org.mitre.oval:tst:3436"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16163" version="5" class="vulnerability" deprecated="true">
      <metadata>
        <title>DEPRECATED: Sun VirtualBox 2.2 through 3.0.2 r49928 allows guest OS users to cause a denial of service (Linux host OS reboot) via a sysenter instruction</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>VirtualBox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2715" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2715"/>
        <description>Sun VirtualBox 2.2 through 3.0.2 r49928 allows guest OS users to cause a denial of service (Linux host OS reboot) via a sysenter instruction.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-04-26T14:33:26.748+04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2013-05-15T15:01:30.989-04:00">DRAFT</status_change>
            <status_change date="2013-06-03T04:02:47.469-04:00">INTERIM</status_change>
            <status_change date="2013-06-24T04:00:07.657-04:00">ACCEPTED</status_change>
            <modified comment="Title indicates Linux but Win platform defined" date="2013-07-26T14:32:26.392-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T14:32:26.392-04:00">DEPRECATED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:16163 - modificated vulnerabilities for VirtualBox" date="2013-12-05T10:43:00.197-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="VirtualBox is installed" definition_ref="oval:org.mitre.oval:def:11581"/>
        <criterion comment="Check if Sun xVM VirtualBox is installed" test_ref="oval:org.mitre.oval:tst:41938"/>
        <criterion comment="Check if Sun xVM VirtualBox version  is greater than or equals to 2.2.0" test_ref="oval:org.mitre.oval:tst:89006"/>
        <criterion comment="Check if Sun xVM VirtualBox version is less than or equals to 3.0.2" test_ref="oval:org.mitre.oval:tst:88902"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1605" version="4" class="vulnerability">
      <metadata>
        <title>URL Redirect Cross Domain Information Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Outlook Express</product>
        </affected>
        <reference ref_id="CVE-2006-2111" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2111" source="CVE"/>
        <description>A component in Microsoft Outlook Express 6 allows remote attackers to bypass domain restrictions and obtain sensitive information via redirections with the mhtml: URI handler, as originally reported for Internet Explorer 6 and 7, aka "URL Redirect Cross Domain Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2007-06-13T08:22:59.000-04:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-06-13T15:20:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-06-29T09:41:58.109-04:00">INTERIM</status_change>
            <status_change date="2007-07-16T09:55:08.204-04:00">ACCEPTED</status_change>
            <modified comment="removed reference to deprecated definition.  corrected reference to Windows Server 2003 definition" date="2009-10-09T13:19:00.587-04:00">
              <contributor organization="The MITRE Corporation">Mike Lah</contributor>
            </modified>
            <status_change date="2009-10-09T13:20:56.618-04:00">INTERIM</status_change>
            <status_change date="2009-10-26T04:00:02.460-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1605 - Correcting incorrect references to 64-bit Itanium XP." date="2012-08-23T17:47:00.168-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-08-23T17:52:32.403-04:00">INTERIM</status_change>
            <status_change date="2012-09-10T04:00:38.978-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Microsoft Outlook Express 6 on Win XP SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Microsoft Outlook Express 6.0 for Windows XP/2003 is installed" definition_ref="oval:org.mitre.oval:def:208"/>
          <criterion comment="the version of inetcomm.dll is less than 6.0.2900.3138" test_ref="oval:org.mitre.oval:tst:3908"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Outlook Express 6 on Win 2k3 SP1">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <extend_definition comment="Microsoft Outlook Express 6.0 for Windows XP/2003 is installed" definition_ref="oval:org.mitre.oval:def:208"/>
          <criterion comment="the version of inetcomm.dll is less than 6.0.3790.2929" test_ref="oval:org.mitre.oval:tst:3966"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Outlook Express 6 on Win 2k3 SP2">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <extend_definition comment="Microsoft Outlook Express 6.0 for Windows XP/2003 is installed" definition_ref="oval:org.mitre.oval:def:208"/>
          <criterion comment="the version of inetcomm.dll is less than 6.0.3790.4073" test_ref="oval:org.mitre.oval:tst:4092"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Outlook Express 6 on Win XP SP2 (64-bit)">
          <extend_definition comment="Microsoft Outlook Express 6.0 for Windows XP/2003 is installed" definition_ref="oval:org.mitre.oval:def:208"/>
          <criterion comment="the version of inetcomm.dll is less than 6.0.3790.4073" test_ref="oval:org.mitre.oval:tst:4092"/>
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Outlook Express 6 on Win XP SP1 (64-bit)">
          <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <extend_definition comment="Microsoft Outlook Express 6.0 for Windows XP/2003 is installed" definition_ref="oval:org.mitre.oval:def:208"/>
          <criterion comment="the version of inetcomm.dll is less than 6.0.3790.2929" test_ref="oval:org.mitre.oval:tst:3966"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1600" version="8" class="vulnerability">
      <metadata>
        <title>Flash Address Bar Spoofing Vulnerability (Win2K)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1626" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1626"/>
        <description>Internet Explorer 6 for Windows XP SP2 and earlier allows remote attackers to spoof the address bar and possibly conduct phishing attacks by re-opening the window to a malicious Shockwave Flash application, then changing the window location back to a trusted URL while the Flash application is still loading.  NOTE: this is a different vulnerability than CVE-2006-1192.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:23.536-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:11.006-04:00">ACCEPTED</status_change>
            <modified comment="Fixed ste:2614: set datatype to version.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:54:00.319-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:59:41.233-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:53.398-05:00">ACCEPTED</status_change>
            <modified comment="Fixed regex in ste:2889.  Implemented by Matthew Wojcik." date="2007-03-06T18:19:00.507-05:00">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2007-03-06T18:21:07.934-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:16:55.782-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:46:05.126-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:01:24.675-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:52.908-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:20.949-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3841.1900" negate="false" test_ref="oval:org.mitre.oval:tst:957"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1597" version="7" class="vulnerability">
      <metadata>
        <title>Win2K/XP,SP1 COM Object Instantiation Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2831" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2831"/>
        <description>Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, aka a variant of the "COM Object Instantiation Memory Corruption Vulnerability," a different vulnerability than CVE-2005-2127.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-12-13T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-16T01:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:46:02.508-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:53.194-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:46:43.883-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:01:23.384-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:59.672-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:20.822-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Win2K or XP,SP1 is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2800.1528" negate="false" test_ref="oval:org.mitre.oval:tst:2390"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1593" class="vulnerability" version="2">
      <metadata>
        <title>Malformed iCal Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Exchange Server</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0039" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0039"/>
        <description>The Exchange Collaboration Data Objects (EXCDO) functionality in Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 allows remote attackers to cause a denial of service (crash) via an Internet Calendar (iCal) file containing multiple X-MICROSOFT-CDO-MODPROPS (MODPROPS) properties in which the second MODPROPS is longer than the first, which triggers a NULL pointer dereference and an unhandled exception.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-05-09T10:04:48">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-05-09T12:53:06-04:00">DRAFT</status_change>
            <status_change date="2007-05-31T15:26:34.040-04:00">INTERIM</status_change>
            <status_change date="2007-06-15T11:07:34.879-04:00">ACCEPTED</status_change>
            <modified comment="References registry value for Common Files directory due to multilingual support" date="2008-04-14T11:07:00.679-04:00">
              <contributor organization="GFI Software">Clifford Farrugia</contributor>
            </modified>
            <status_change date="2008-04-14T12:26:45.215-04:00">INTERIM</status_change>
            <status_change date="2008-05-05T04:00:11.538-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Microsoft Exchange 2000 Server Service Pack 3" operator="AND">
          <extend_definition comment="Microsoft Exchange 2000 Server Service Pack 3 is installed" definition_ref="oval:org.mitre.oval:def:1858"/>
          <criterion comment="the version of Cdoex.dll is less than 6.0.6619.12" test_ref="oval:org.mitre.oval:tst:3975"/>
        </criteria>
        <criteria comment="Microsoft Exchange Server 2003 Service Pack 1" operator="AND">
          <extend_definition comment="Microsoft Exchange Server 2003 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:1672"/>
          <criterion comment="the version of Cdoex.dll is less than 6.5.7235.2" test_ref="oval:org.mitre.oval:tst:3925"/>
        </criteria>
        <criteria comment="Microsoft Exchange Server 2003 Service Pack 2" operator="AND">
          <extend_definition comment="Microsoft Exchange Server 2003 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:1869"/>
          <criterion comment="the version of Cdoex.dll is less than 6.5.7652.24" test_ref="oval:org.mitre.oval:tst:3618"/>
        </criteria>
        <criteria comment="Microsoft Exchange Server 2007" operator="AND">
          <extend_definition comment="Microsoft Exchange Server 2007 is installed" definition_ref="oval:org.mitre.oval:def:1641"/>
          <criterion comment="the version of Cdoex.dll is less than 8.0.709.0" test_ref="oval:org.mitre.oval:tst:4122"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1590" version="8" class="vulnerability">
      <metadata>
        <title>ART Image Rendering Vulnerability (2K/XP)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2378" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2378"/>
        <description>Buffer overflow in the ART Image Rendering component (jgdw400.dll) in Microsoft Windows XP SP1 and Sp2, Server 2003 SP1 and earlier, and Windows 98 and Me allows remote attackers to execute arbitrary code via a crafted ART image that causes heap corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:22.899-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:09.888-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:46:06.325-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:52.986-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1590 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:06:33.515-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:01:22.386-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:59.014-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:20.636-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Win2K or XP,SP1 is installed">
          <criterion comment="Windows 2000 is installed" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003/Vista service pack 1 is installed" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="Internet Explorer 6 Service Pack 1 is installed" test_ref="oval:org.mitre.oval:tst:2919"/>
        <criterion comment="the version of jgdw400.dll is less than 106.0.0.0" test_ref="oval:org.mitre.oval:tst:835"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1589" version="9" class="vulnerability">
      <metadata>
        <title>IE6 COM Object Instantiation Memory Corruption (Win2K/XP,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1186" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1186"/>
        <description>Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via by instantiating the (1) Mdt2gddr.dll, (2) Mdt2dd.dll, and (3) Mdt2gddo.dll COM objects as ActiveX controls, which leads to memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added an anchor to the regex used to check for Internet Explorer 6." date="2007-01-11T20:38:00.950-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-01-11T20:49:14.089-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:52.729-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:2185 - Anchored regular expression" date="2011-02-22T12:51:00.261-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:52:31.995-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:00:47.372-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:46:35.905-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:01:21.972-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:58.269-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:20.491-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Win2K or XP,SP1 is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="Internet Explorer 6 (any patch level) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2333"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2800.1543" negate="false" test_ref="oval:org.mitre.oval:tst:2332"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1583" version="4" class="vulnerability">
      <metadata>
        <title>Win2K Kernel Privilege Escalation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2827" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2827"/>
        <description>The thread termination routine in the kernel for Windows NT 4.0 and 2000 (NTOSKRNL.EXE) allows local users to modify kernel memory and execution flow via steps in which a terminating thread causes Asynchronous Procedure Call (APC) entries to free the wrong data, aka the "Windows Kernel Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-12-13T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-16T01:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Changed obj:633 to use var:200 to get the Windows System 32 directory." date="2007-01-04T08:58:00.479-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-01-04T09:00:02.619-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:52.531-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1583 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:05:37.602-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:15.331-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Windows 2000 is installed" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="The version of Ntkrnlpa.exe is less than 5.0.2195.7071" test_ref="oval:org.mitre.oval:tst:839"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15781" version="5" class="vulnerability">
      <metadata>
        <title>Reflected XSS Vulnerability - MS12-062</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft System Center Configuration Manager 2007</product>
          <product>Microsoft System Center Configuration Manager 2007 R2</product>
          <product>Microsoft System Center Configuration Manager 2007 R3</product>
          <product>Microsoft Systems Management Server 2003</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2012-2536" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2536"/>
        <description>Cross-site scripting (XSS) vulnerability in Microsoft Systems Management Server 2003 SP3 and System Center Configuration Manager 2007 SP2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Reflected XSS Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2012-09-13T09:31:18">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-09-13T12:48:30.646-04:00">DRAFT</status_change>
            <status_change date="2012-10-01T04:00:30.570-04:00">INTERIM</status_change>
            <status_change date="2012-10-22T04:06:44.168-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:80096 - Updates based on revised bulletin for MS12-062." date="2012-11-19T16:12:00.903-05:00">
              <contributor organization="SecPod Technologies">Pradeep R B</contributor>
            </modified>
            <status_change date="2012-11-19T16:20:34.844-05:00">INTERIM</status_change>
            <status_change date="2012-12-10T04:00:13.311-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for vulnerable SMS 2003/file version">
          <extend_definition comment="Microsoft Systems Management Server 2003 SP3 is installed" definition_ref="oval:org.mitre.oval:def:15150"/>
          <criterion comment="Check if version of ReportingInstall.exe (SMS 2003) is less than 2.50.4253.3129" test_ref="oval:org.mitre.oval:tst:80064"/>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable SCCM 2007/file version">
          <criterion comment="Check if version of ReportingInstall.exe (SCCM 2007) is less than 4.0.6487.2216" test_ref="oval:org.mitre.oval:tst:80096"/>
          <criteria operator="OR" comment="Either applications">
            <extend_definition comment="Microsoft System Center Configuration Manager 2007 SP2 is installed" definition_ref="oval:org.mitre.oval:def:15636"/>
            <extend_definition comment="Microsoft System Center Configuration Manager 2007 R2 is installed" definition_ref="oval:org.mitre.oval:def:15840"/>
            <extend_definition comment="Microsoft System Center Configuration Manager 2007 R3 is installed" definition_ref="oval:org.mitre.oval:def:15833"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15840" version="3" class="inventory">
      <metadata>
        <title>Microsoft System Center Configuration Manager 2007 R2 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft System Center Configuration Manager 2007 R2</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:systems_management_server:2007:r2"/>
        <description>Microsoft System Center Configuration Manager 2007 R2 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2012-09-13T09:31:18">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-09-13T12:48:30.145-04:00">DRAFT</status_change>
            <status_change date="2012-10-01T04:00:35.776-04:00">INTERIM</status_change>
            <status_change date="2012-10-22T04:06:46.648-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Microsoft System Center Configuration Manager 2007 R2 is installed" test_ref="oval:org.mitre.oval:tst:80002"/>
        <extend_definition comment="Microsoft System Center Configuration Manager 2007 is installed" definition_ref="oval:org.mitre.oval:def:15678"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15833" version="3" class="inventory">
      <metadata>
        <title>Microsoft System Center Configuration Manager 2007 R3 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft System Center Configuration Manager 2007 R3</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:systems_management_server:2007:r3"/>
        <description>Microsoft System Center Configuration Manager 2007 R3 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2012-09-13T09:31:18">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-09-13T12:48:30.433-04:00">DRAFT</status_change>
            <status_change date="2012-10-01T04:00:35.255-04:00">INTERIM</status_change>
            <status_change date="2012-10-22T04:06:46.379-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Microsoft System Center Configuration Manager 2007 R3 is installed" test_ref="oval:org.mitre.oval:tst:79954"/>
        <extend_definition comment="Microsoft System Center Configuration Manager 2007 is installed" definition_ref="oval:org.mitre.oval:def:15678"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15636" version="3" class="inventory">
      <metadata>
        <title>Microsoft System Center Configuration Manager 2007 SP2 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft System Center Configuration Manager 2007</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:systems_management_server:2007:sp2"/>
        <description>Microsoft System Center Configuration Manager 2007 SP2 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2012-09-13T18:48:18">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-09-13T12:48:29.178-04:00">DRAFT</status_change>
            <status_change date="2012-10-01T04:00:17.770-04:00">INTERIM</status_change>
            <status_change date="2012-10-22T04:06:35.953-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft System Center Configuration Manager 2007 is installed" definition_ref="oval:org.mitre.oval:def:15678"/>
        <criterion comment="Check if Microsoft System Center Configuration Manager 2007 SP2 is installed" test_ref="oval:org.mitre.oval:tst:80097"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15678" version="3" class="inventory">
      <metadata>
        <title>Microsoft System Center Configuration Manager 2007 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft System Center Configuration Manager 2007</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:systems_management_server:2007"/>
        <description>Microsoft System Center Configuration Manager 2007 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2012-09-13T18:48:18">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-09-13T12:48:28.852-04:00">DRAFT</status_change>
            <status_change date="2012-10-01T04:00:21.696-04:00">INTERIM</status_change>
            <status_change date="2012-10-22T04:06:37.946-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Microsoft System Center Configuration Manager 2007 is installed" test_ref="oval:org.mitre.oval:tst:80024"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15150" version="3" class="inventory">
      <metadata>
        <title>Microsoft Systems Management Server 2003 SP3 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Systems Management Server 2003</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:systems_management_server:2003:sp3"/>
        <description>Microsoft Systems Management Server 2003 SP3 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2012-09-13T18:48:18">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-09-13T12:48:29.676-04:00">DRAFT</status_change>
            <status_change date="2012-10-01T04:00:07.264-04:00">INTERIM</status_change>
            <status_change date="2012-10-22T04:06:06.888-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Systems Management Server 2003 is installed" definition_ref="oval:org.mitre.oval:def:15121"/>
        <criterion comment="Check if Microsoft Systems Management Server 2003 SP3 is installed" test_ref="oval:org.mitre.oval:tst:79365"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15121" version="3" class="inventory">
      <metadata>
        <title>Microsoft Systems Management Server 2003 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Systems Management Server 2003</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:systems_management_server:2003"/>
        <description>Microsoft Systems Management Server 2003 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2012-09-13T18:48:18">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-09-13T12:48:29.443-04:00">DRAFT</status_change>
            <status_change date="2012-10-01T04:00:06.995-04:00">INTERIM</status_change>
            <status_change date="2012-10-22T04:06:05.660-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Microsoft Systems Management Server 2003 is installed" test_ref="oval:org.mitre.oval:tst:80078"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1578" version="6" class="vulnerability">
      <metadata>
        <title>Windows Media Player 7.10 Bitmap Remote Code Execution</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows Media Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0006" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0006"/>
        <description>Heap-based buffer overflow in the bitmap processing routine in Microsoft Windows Media Player 7.1 on Windows 2000 SP4, Media Player 9 on Windows 2000 SP4 and XP SP1, and Media Player 10 on XP SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted bitmap (.BMP) file that specifies a size of 0 but contains additional data.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-17T07:36:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-22T08:27:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:952" date="2007-01-24T21:37:00.382-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-01-24T21:38:24.641-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:52.347-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:952 - def:5942 &amp; def:5689, Enhanced to cover WinVista, 2008, 2003 &amp; also 64-bit with service packs" date="2011-11-15T14:56:00.873-05:00">
              <contributor organization="SecPod Technologies">Pradeep R B</contributor>
            </modified>
            <status_change date="2011-11-15T14:58:49.714-05:00">INTERIM</status_change>
            <status_change date="2011-12-05T04:00:24.013-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:952 - Updated series of States to escape .(period) character." date="2012-01-13T17:30:00.463-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-01-13T17:34:55.577-05:00">INTERIM</status_change>
            <status_change date="2012-01-30T04:00:57.549-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Media Player 7.1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1066"/>
        <criterion comment="the version of Wmpui.dll is less than 7.10.0.3077" negate="false" test_ref="oval:org.mitre.oval:tst:846"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15763" version="8" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the VirtualBox component in Oracle Virtualization 4.0, 4.1, and 4.2</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>VirtualBox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-0420" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0420"/>
        <description>Unspecified vulnerability in the VirtualBox component in Oracle Virtualization 4.0, 4.1, and 4.2 allows local users to affect integrity and availability via unknown vectors related to Core.  NOTE: The previous information was obtained from the January 2013 Oracle CPU. Oracle has not commented on claims from another vendor that this issue is related to an incorrect comparison in the vga_draw_text function in Devices/Graphics/DevVGA.cpp, which can cause VirtualBox to "draw more lines than necessary."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-04-26T14:33:26.748+04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2013-05-15T15:01:32.094-04:00">DRAFT</status_change>
            <status_change date="2013-06-03T04:02:41.713-04:00">INTERIM</status_change>
            <status_change date="2013-06-24T04:00:05.202-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15297 - modificated vulnerabilities for VirtualBox" date="2013-12-05T10:43:00.197-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-05T10:45:12.446-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:00:31.967-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:15763 - New vulnerability(CVE-2013-5892) added and modified existing criteria" date="2014-01-30T14:45:00.034-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-30T14:49:22.119-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:10.655-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="VirtualBox is installed" definition_ref="oval:org.mitre.oval:def:11581"/>
        <criterion comment="Check if Oracle VM VirtualBox is installed" test_ref="oval:org.mitre.oval:tst:42006"/>
        <criteria operator="OR" comment="Check versions of VirtualBox">
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.0.0" test_ref="oval:org.mitre.oval:tst:88607"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than or equals to 4.0.6" test_ref="oval:org.mitre.oval:tst:88945"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version  is greater than or equals to 4.0.8" test_ref="oval:org.mitre.oval:tst:88912"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than 4.3.0" test_ref="oval:org.mitre.oval:tst:99835"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1571" version="3" class="vulnerability">
      <metadata>
        <title>WMF Denial of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1211" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1211"/>
        <description>Unspecified kernel GDI functions in Microsoft Windows 2000 SP4; XP SP2; and Server 2003 Gold, SP1, and SP2 allows user-assisted remote attackers to cause a denial of service (possibly persistent restart) via a crafted Windows Metafile (WMF) image that causes an invalid dereference of an offset in a kernel structure, a related issue to CVE-2005-4560.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-04-09T09:49:32">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-04-09T11:20:00.000-05:00">DRAFT</status_change>
            <status_change date="2007-04-25T19:52:17.927-04:00">INTERIM</status_change>
            <modified comment="Removed Vista criteria section and affected platform metadata; MS07-017 says it's not affected.  Altered S03 section of criteria to reference proper Gdi32.dll file versions for S03,SP1 and S03,SP2." date="2007-04-26T13:34:00.645-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-05-23T15:05:29.591-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1571 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:05:19.497-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:14.281-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="gdi32.dll version is less than 5.0.2195.7133" test_ref="oval:org.mitre.oval:tst:3337"/>
        </criteria>
        <criteria operator="AND" comment="Windows XP SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="gdi32.dll version is less than 5.1.2600.3099" test_ref="oval:org.mitre.oval:tst:3215"/>
        </criteria>
        <criteria operator="AND" comment="Windows Server 2003 Gold">
          <extend_definition comment="Microsoft Windows Server 2003 (x86) Gold is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="gdi32.dll version is less than 5.2.3790.651" test_ref="oval:org.mitre.oval:tst:4019"/>
        </criteria>
        <criteria operator="AND" comment="Windows Server 2003 SP1">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="gdi32.dll version is less than 5.2.3790.2892" test_ref="oval:org.mitre.oval:tst:3548"/>
        </criteria>
        <criteria operator="AND" comment="Windows Server 2003 SP2">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <criterion comment="gdi32.dll version is less than 5.2.3790.4033" test_ref="oval:org.mitre.oval:tst:3612"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1570" version="1" class="vulnerability">
      <metadata>
        <title>Excel Viewer 2003 Remote Code Execution via Malformed Description</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Office</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0029" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0029"/>
        <description>Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed description, which leads to memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-15T10:53:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-15T07:17:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Xlview.exe is installed with a version less than 11.0.8012.0" negate="false" test_ref="oval:org.mitre.oval:tst:881"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:157" version="3" class="vulnerability">
      <metadata>
        <title>MFC Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0025" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0025"/>
        <description>The MFC component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1 and Visual Studio .NET 2000, 2002 SP1, 2003, and 2003 SP1 allows user-assisted remote attackers to execute arbitrary code via an RTF file with a malformed OLE object that triggers memory corruption. NOTE: this might be due to a stack-based buffer overflow in the AfxOleSetEditMenu function in MFC42u.dll.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-02-14T09:49:32">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-02-16T21:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:16:54.679-04:00">INTERIM</status_change>
            <status_change date="2007-04-10T13:44:20.592-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:157 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:06:45.577-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:13.461-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win2K,SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Mfc40u.dll is less than 4.1.0.6141" test_ref="oval:org.mitre.oval:tst:3685"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of Mfc40u.dll is less than 4.1.0.6141" test_ref="oval:org.mitre.oval:tst:3685"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP1 (64-bit)">
          <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="a version of Windows for the ia64 architecture is installed" test_ref="oval:org.mitre.oval:tst:2747"/>
          <criterion comment="the version of Mfc42u.dll is less than 6.5.9146.0" test_ref="oval:org.mitre.oval:tst:4026"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP1 (64-bit)">
          <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion negate="true" comment="a version of Windows for the ia64 architecture is installed" test_ref="oval:org.mitre.oval:tst:2747"/>
          <criterion comment="the version of Mfc42u.dll is less than 6.0.9792.0" test_ref="oval:org.mitre.oval:tst:3532"/>
        </criteria>
        <criteria operator="AND" comment="S03 (x86)">
          <criterion comment="Windows Server 2003 is installed" test_ref="oval:org.mitre.oval:tst:2761"/>
          <criterion negate="true" comment="a version of Windows for the ia64 architecture is installed" test_ref="oval:org.mitre.oval:tst:2747"/>
          <criterion comment="the version of Mfc40u.dll is less than 4.1.0.6141" test_ref="oval:org.mitre.oval:tst:3685"/>
        </criteria>
        <criteria operator="AND" comment="S03,SP1">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="a version of Windows for the ia64 architecture is installed" test_ref="oval:org.mitre.oval:tst:2747"/>
          <criterion comment="the version of Mfc42u.dll is less than 6.5.9146.0" test_ref="oval:org.mitre.oval:tst:4026"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Visual Studio .NET 2002">
          <extend_definition comment="Microsoft Visual Studio .NET 2002 is installed" definition_ref="oval:org.mitre.oval:def:1131"/>
          <criterion comment="the version of Mfc70.dll is less than 7.0.9801.0" test_ref="oval:org.mitre.oval:tst:3488"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Visual Studio .NET 2002 Service Pack 1">
          <extend_definition comment="Microsoft Visual Studio .NET 2002 SP1 is installed" definition_ref="oval:org.mitre.oval:def:981"/>
          <criterion comment="the version of Mfc70.dll is less than 7.0.9975.0" test_ref="oval:org.mitre.oval:tst:4011"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Visual Studio .NET 2003">
          <extend_definition comment="Microsoft Visual Studio .NET 2003 is installed" definition_ref="oval:org.mitre.oval:def:166"/>
          <criterion comment="the version of Mfc71.dll is less than 7.10.5057.0" test_ref="oval:org.mitre.oval:tst:3844"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Visual Studio .NET 2003 Service Pack 1">
          <extend_definition comment="Microsoft Visual Studio .NET 2003 SP1 is installed" definition_ref="oval:org.mitre.oval:def:168"/>
          <criterion comment="the version of Mfc71.dll is less than 7.10.6041.0" test_ref="oval:org.mitre.oval:tst:3815"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:981" version="5" class="inventory">
      <metadata>
        <title>Microsoft Visual Studio .NET 2002 SP1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:visual_studio_.net:2002:SP1"/>
        <description>Microsoft Visual Studio .NET 2002 SP1 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-02-14T09:49:32">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-02-16T21:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:17:29.144-04:00">INTERIM</status_change>
            <status_change date="2007-04-10T13:44:29.181-04:00">ACCEPTED</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.378-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-10-25T16:51:17.911-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:01:21.771-05:00">ACCEPTED</status_change>
            <modified date="2008-03-02T04:44:54" comment="Added file check to ensure a full installation.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2008-03-17T04:00:24.075-04:00">ACCEPTED</status_change>
            <modified date="2009-06-15T04:44:54" comment="Added CPE">
              <contributor organization="The MITRE Corporation">Brendan Miles</contributor>
            </modified>
            <status_change date="2009-06-22T04:00:54.806-04:00">INTERIM</status_change>
            <status_change date="2009-07-13T04:00:58.429-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="devenv.exe exists as a Microsoft Visual Studio 2002 component" test_ref="oval:org.mitre.oval:tst:7813"/>
        <criterion comment="Service Pack 1 for Microsoft Visual Studio .NET 2002 is installed" test_ref="oval:org.mitre.oval:tst:3317"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:168" version="9" class="inventory">
      <metadata>
        <title>Microsoft Visual Studio .NET 2003 SP1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:visual_studio_.net:2003:sp1"/>
        <description>Microsoft Visual Studio .NET 2003 SP1 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-02-14T09:49:32">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-02-16T21:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:16:59.273-04:00">INTERIM</status_change>
            <status_change date="2007-04-10T13:44:22.175-04:00">ACCEPTED</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.378-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-10-25T16:51:17.649-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:01:01.364-05:00">ACCEPTED</status_change>
            <modified date="2008-03-02T04:44:54" comment="Added file check to ensure a full installation.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2008-03-17T04:00:17.981-04:00">ACCEPTED</status_change>
            <modified date="2009-06-15T04:44:54" comment="Added CPE">
              <contributor organization="The MITRE Corporation">Brendan Miles</contributor>
            </modified>
            <status_change date="2009-06-22T04:00:50.418-04:00">INTERIM</status_change>
            <status_change date="2009-07-13T04:00:28.042-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:168 - Modifications vary from minor OVAL title/description changes to suggesting an alternative CPE name to use." date="2011-09-28T11:29:00.976-04:00">
              <contributor organization="The MITRE Corporation">David Rothenberg</contributor>
            </modified>
            <status_change date="2011-09-28T11:33:15.228-04:00">INTERIM</status_change>
            <status_change date="2011-10-17T04:00:12.929-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:48.868-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:48.868-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:02:57.903-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="devenv.exe exists as a Microsoft Visual Studio 2003 component" test_ref="oval:org.mitre.oval:tst:7817"/>
        <criterion comment="Service Pack 1 for Microsoft Visual Studio .NET 2003 is installed" test_ref="oval:org.mitre.oval:tst:3648"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:166" version="6" class="inventory">
      <metadata>
        <title>Microsoft Visual Studio .NET 2003 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:visual_studio_.net:2003"/>
        <description>Microsoft Visual Studio .NET 2003 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-02-14T09:49:32">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-02-16T21:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:16:58.485-04:00">INTERIM</status_change>
            <status_change date="2007-04-10T13:44:21.203-04:00">ACCEPTED</status_change>
            <modified date="2008-03-02T04:44:54" comment="Added file check to ensure a full installation.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2008-03-17T04:00:17.442-04:00">ACCEPTED</status_change>
            <modified date="2009-06-15T04:44:54" comment="Added CPE">
              <contributor organization="The MITRE Corporation">Brendan Miles</contributor>
            </modified>
            <status_change date="2009-06-22T04:00:50.087-04:00">INTERIM</status_change>
            <status_change date="2009-07-13T04:00:22.776-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:166 - modified inventories for Microsoft Expression Design." date="2013-07-05T09:53:00.264-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-05T09:57:59.362-04:00">INTERIM</status_change>
            <status_change date="2013-07-22T04:00:58.244-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="devenv.exe exists as a Microsoft Visual Studio 2003 component" test_ref="oval:org.mitre.oval:tst:7817"/>
        <criterion comment="Registry key specifying where Microsoft Visual Studio 2003 exists" test_ref="oval:org.mitre.oval:tst:80757"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1131" version="8" class="inventory">
      <metadata>
        <title>Microsoft Visual Studio .NET 2002 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:visual_studio_.net:2002"/>
        <description>Microsoft Visual Studio .NET 2002 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2007-02-14T09:49:32">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-02-16T21:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:16:42.605-04:00">INTERIM</status_change>
            <status_change date="2007-04-10T13:44:18.576-04:00">ACCEPTED</status_change>
            <modified date="2008-03-02T04:44:54" comment="Added file check to ensure a full installation.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2008-03-17T04:00:15.343-04:00">ACCEPTED</status_change>
            <modified comment="Added CPE name" date="2009-05-25T10:32:00.713-04:00">
              <contributor organization="The MITRE Corporation">Brendan Miles</contributor>
            </modified>
            <status_change date="2009-05-25T10:32:00.713-04:00">INTERIM</status_change>
            <status_change date="2009-06-15T04:00:30.881-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1131 - Modifications vary from minor OVAL title/description changes to suggesting an alternative CPE name to use." date="2011-09-28T11:29:00.976-04:00">
              <contributor organization="The MITRE Corporation">David Rothenberg</contributor>
            </modified>
            <status_change date="2011-09-28T11:33:45.690-04:00">INTERIM</status_change>
            <status_change date="2011-10-17T04:00:03.417-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1131 - modified inventories for Microsoft Expression Design." date="2013-07-05T09:53:00.264-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-05T09:58:07.859-04:00">INTERIM</status_change>
            <status_change date="2013-07-22T04:00:04.258-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="devenv.exe exists as a Microsoft Visual Studio 2002 component" test_ref="oval:org.mitre.oval:tst:7813"/>
        <criterion comment="Registry key specifying where Microsoft Visual Studio 2002 exists" test_ref="oval:org.mitre.oval:tst:81310"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1569" version="9" class="vulnerability">
      <metadata>
        <title>IE6 Multiple Event Handler Memory Corruption (Win2K/XP,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1245" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1245"/>
        <description>Buffer overflow in mshtml.dll in Microsoft Internet Explorer 6.0.2900.2180, and probably other versions, allows remote attackers to execute arbitrary code via an HTML tag with a large number of script action handlers such as onload and onmouseover, as demonstrated using onclick, aka the "Multiple Event Handler Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added an anchor to the regex used to check for Internet Explorer 6." date="2007-01-11T20:38:00.950-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-01-11T20:49:16.449-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:52.045-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:2185 - Anchored regular expression" date="2011-02-22T12:51:00.261-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:52:29.545-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:00:46.922-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:46:20.488-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:01:20.956-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:55.239-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:20.333-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Win2K or XP,SP1 is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="Internet Explorer 6 (any patch level) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2333"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2800.1543" negate="false" test_ref="oval:org.mitre.oval:tst:2332"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1567" version="8" class="vulnerability">
      <metadata>
        <title>Address Bar Spoofing Vulnerability (Win2K)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2384" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2384"/>
        <description>Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remote attackers to conduct spoofing and phishing attacks by using a modal browser window in a way that preserves the original address bar and trusted UI of a trusted site, even after the browser has been navigated to a malicious site, aka the "Address Bar Spoofing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:21.998-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:08.495-04:00">ACCEPTED</status_change>
            <modified comment="Fixed ste:2614: set datatype to version.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:54:00.319-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:59:42.822-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:51.521-05:00">ACCEPTED</status_change>
            <modified comment="Fixed regex in ste:2889.  Implemented by Matthew Wojcik." date="2007-03-06T18:19:00.507-05:00">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2007-03-06T18:21:08.993-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:16:54.306-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:46:20.831-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:01:20.620-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:55.580-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:20.181-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3841.1900" negate="false" test_ref="oval:org.mitre.oval:tst:957"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15654" version="5" class="vulnerability">
      <metadata>
        <title>Win32k Incorrect Type Handling Vulnerability - MS12-047</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2012-1893" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1893"/>
        <description>win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate callback parameters during creation of a hook procedure, which allows local users to gain privileges via a crafted application, aka "Win32k Incorrect Type Handling Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2012-07-13T10:19:21">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-07-13T11:37:14.010-04:00">DRAFT</status_change>
            <status_change date="2012-07-30T04:00:33.452-04:00">INTERIM</status_change>
            <status_change date="2012-08-20T04:00:10.344-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:12547 - Submission on Microsoft Bulletin for the month April 2013." date="2013-04-15T21:59:00.487-04:00">
              <contributor organization="SecPod Technologies">Sharath S</contributor>
            </modified>
            <status_change date="2013-04-15T22:09:08.521-04:00">INTERIM</status_change>
            <status_change date="2013-05-06T04:01:39.018-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows XP X86 and vuln file version">
          <criterion comment="Check if the version of Win32k.sys is less than 5.1.2600.6244" test_ref="oval:org.mitre.oval:tst:79968"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
        </criteria>
        <criteria operator="AND" comment="Win XP X64 / 2K3 vulnerable file version">
          <criteria operator="OR" comment="Win XP X64 / 2k3">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="Check if the version of Win32k.sys is less than 5.2.3790.5019" test_ref="oval:org.mitre.oval:tst:79689"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2k8 and vulnerable file version">
          <criteria operator="OR" comment="Vista/2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable file version">
            <criterion comment="Check if the version of Win32k.sys is less than 6.0.6002.18647" test_ref="oval:org.mitre.oval:tst:79788"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is less than 6.0.6002.22876" test_ref="oval:org.mitre.oval:tst:79649"/>
              <criterion comment="the version of win32k.sys is greater than or equal to 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:43635"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 and 2K8R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 7 / 2k8 R2">
            <extend_definition comment="Microsoft Windows 7 is installed" definition_ref="oval:org.mitre.oval:def:12541"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Win32K.sys is less than 6.1.7600.17039" test_ref="oval:org.mitre.oval:tst:79650"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32K.sys is less than 6.1.7600.21231" test_ref="oval:org.mitre.oval:tst:79215"/>
              <criterion comment="the version of win32k.sys is greater than or equal to 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:27587"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / 2K8 R2 SP1 and vulnerable file version">
          <criteria operator="OR" comment="Win 7 SP1  / 2k8 R2 SP1">
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Win32K.sys is less than 6.1.7601.17860" test_ref="oval:org.mitre.oval:tst:79504"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is less than 6.1.7601.22016" test_ref="oval:org.mitre.oval:tst:79969"/>
              <criterion comment="the version of win32k.sys is greater than or equal to 6.1.7601.21000" test_ref="oval:org.mitre.oval:tst:42715"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12541" version="5" class="inventory">
      <metadata>
        <title>Microsoft Windows 7 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_7"/>
        <description>The operating system installed on the system is Microsoft Windows 7.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-06-23T00:00:00Z"/>
            <status_change date="2011-06-29T14:09:45.698-04:00">DRAFT</status_change>
            <status_change date="2011-07-18T04:00:16.416-04:00">INTERIM</status_change>
            <status_change date="2011-08-08T04:00:24.675-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5027 - removed extraneous whitespace from regex" date="2015-05-21T13:26:00.569-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-05-21T13:29:02.806-04:00">INTERIM</status_change>
            <status_change date="2015-06-08T04:00:07.716-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criterion comment="Windows 7 is installed" test_ref="oval:org.mitre.oval:tst:10792"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1563" version="5" class="vulnerability">
      <metadata>
        <title>IE v6.0,SP1 Drag-and-Drop Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0839" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0839"/>
        <description>Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by "wottapoop.html".</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-25T04:59:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-27T01:04:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-17T10:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-27T10:50:00.000-04:00" comment="modified wft-564 - Changed test to match comment">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:45:56.455-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:51.240-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:55.954-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:20.002-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1476" negate="false" test_ref="oval:org.mitre.oval:tst:856"/>
          <criterion comment="the patch kb834707 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:855"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1561" version="7" class="vulnerability">
      <metadata>
        <title>Windows Kernel LPC Privilege Escalation Vulnerability (Windows 2000)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0893" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0893"/>
        <description>The Local Procedure Call (LPC) interface of the Windows Kernel for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the lengths of messages sent to the LPC port, which allows local users to gain privileges, aka "Windows Kernel Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-12-16T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-12T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-17T12:00:00.000-04:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2005-06-22T12:35:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected and tightened regular expression in ste:2610" date="2010-12-02T11:46:00.307-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-12-02T11:47:26.441-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:34.310-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:46:15.727-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:01:19.923-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 (sp4 or earlier) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 5 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2790"/>
        </criteria>
        <criterion comment="The version of Ntoskrnl.exe is less than 5.0.2195.6992" negate="false" test_ref="oval:org.mitre.oval:tst:857"/>
        <criterion comment="the patch kb885835is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2622"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1558" version="8" class="vulnerability">
      <metadata>
        <title>Win2K,SP4 COM Object Instantiation Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2831" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2831"/>
        <description>Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, aka a variant of the "COM Object Instantiation Memory Corruption Vulnerability," a different vulnerability than CVE-2005-2127.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-12-13T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-16T01:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed ste:2614: set datatype to version.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:54:00.319-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:59:42.445-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:50.963-05:00">ACCEPTED</status_change>
            <modified comment="Fixed regex in ste:2889.  Implemented by Matthew Wojcik." date="2007-03-06T18:19:00.507-05:00">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2007-03-06T18:21:13.318-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:16:53.639-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:24.697-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:01:19.562-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:38.519-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:19.872-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3835.2200" negate="false" test_ref="oval:org.mitre.oval:tst:893"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:155" version="3" class="vulnerability">
      <metadata>
        <title>User Profile Elevation of Privilege Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference ref_id="CVE-2006-3443" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3443" source="CVE"/>
        <description>Untrusted search path vulnerability in Winlogon in Microsoft Windows 2000 SP4, when SafeDllSearchMode is disabled, allows local users to gain privileges via a malicious DLL in the UserProfile directory, aka "User Profile Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:28:46.723-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:57:22.199-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:155 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:06:15.793-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:12.715-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win2K,SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="The version of Kernel32.dll is less than 5.0.2195.7099." test_ref="oval:org.mitre.oval:tst:80"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP1">
          <extend_definition comment="Microsoft Windows XP SP1 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          <criterion comment="The version of Kernel32.dll is less than 5.1.2600.1869." test_ref="oval:org.mitre.oval:tst:31"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="The version of Kernel32.dll is less than 5.1.2600.2945." test_ref="oval:org.mitre.oval:tst:45"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP1 (64-bit)">
          <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="The version of Kernel32.dll is less than 5.2.3790.2741." test_ref="oval:org.mitre.oval:tst:104"/>
        </criteria>
        <criteria operator="AND" comment="S03-Gold">
          <extend_definition comment="Microsoft Windows Server 2003 (x86) Gold is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="The version of Kernel32.dll is less than 5.2.3790.556." test_ref="oval:org.mitre.oval:tst:63"/>
        </criteria>
        <criteria operator="AND" comment="S03,SP1">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="The version of Kernel32.dll is less than 5.2.3790.2741." test_ref="oval:org.mitre.oval:tst:104"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1548" version="3" class="vulnerability">
      <metadata>
        <title>Mozilla Downloading Executables with "Save Image As..."</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1736" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1736"/>
        <description>Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to trick users into downloading and saving an executable file via an image that is overlaid by a transparent image link that points to the executable, which causes the executable to be saved when the user clicks the "Save image as..." option.  NOTE: this attack is made easier due to a GUI truncation issue that prevents the user from seeing the malicious extension when there is extra whitespace in the filename.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-07T09:05:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:21.133-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:1133" date="2007-02-26T08:08:00.208-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-26T08:09:14.571-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:1138" date="2007-02-26T08:25:00.405-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:2283" date="2007-02-26T08:29:00.407-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:2284" date="2007-02-26T08:30:00.724-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:53.268-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:881" date="2007-04-23T12:05:00.811-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:12:52.572-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:883" date="2007-04-23T12:05:00.804-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in obj:1385" date="2007-04-23T12:05:00.430-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:10:54.838-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1268"/>
          <criterion comment="Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1267"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.12 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1264"/>
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1263"/>
        </criteria>
        <criteria operator="AND" comment="A pre-release of SeaMonkey 1.0 is installed">
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2439"/>
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2438"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:154" class="vulnerability" version="1">
      <metadata>
        <title>Microsoft Agent Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3445" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3445"/>
        <description>Integer overflow in the ReadWideString function in agentdpv.dll in Microsoft Agent on Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via a large length value in an .ACF file, which results in a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-11-15T12:28:05">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-11-17T12:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:53:49.969-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:49.634-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Win2K,SP4" operator="AND">
          <extend_definition comment="Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of agentdpv.dll is less than 2.0.0.3424" test_ref="oval:org.mitre.oval:tst:195"/>
        </criteria>
        <criteria comment="WinXP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of agentdpv.dll is less than 2.0.0.3424" test_ref="oval:org.mitre.oval:tst:195"/>
        </criteria>
        <criteria comment="WinXP,SP1 (64-bit)" operator="AND">
          <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="the version of agentdpv.dll is less than 5.2.3790.1242" test_ref="oval:org.mitre.oval:tst:109"/>
        </criteria>
        <criteria comment="S03-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="the version of agentdpv.dll is less than 2.0.0.3424" test_ref="oval:org.mitre.oval:tst:195"/>
        </criteria>
        <criteria comment="S03,SP1" operator="AND">
          <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of agentdpv.dll is less than 5.2.3790.1242" test_ref="oval:org.mitre.oval:tst:109"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1538" version="4" class="vulnerability">
      <metadata>
        <title>Win2K/XP,SP1 DDS Library Shape Control Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2127" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2127"/>
        <description>Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, as originally demonstrated using the (1) DDS Library Shape Control (Msdds.dll) COM object, and other objects including (2) Blnmgrps.dll, (3) Ciodm.dll, (4) Comsvcs.dll, (5) Danim.dll, (6) Htmlmarq.ocx, (7) Mdt2dd.dll (as demonstrated using a heap corruption attack with uninitialized memory), (8) Mdt2qd.dll, (9) Mpg4ds32.ax, (10) Msadds32.ax, (11) Msb1esen.dll, (12) Msb1fren.dll, (13) Msb1geen.dll, (14) Msdtctm.dll, (15) Mshtml.dll, (16) Msoeacct.dll, (17) Msosvfbr.dll, (18) Mswcrun.dll, (19) Netshell.dll, (20) Ole2disp.dll, (21) Outllib.dll, (22) Psisdecd.dll, (23) Qdvd.dll, (24) Repodbc.dll, (25) Shdocvw.dll, (26) Shell32.dll, (27) Soa.dll, (28) Srchui.dll, (29) Stobject.dll, (30) Vdt70.dll, (31) Vmhelper.dll, and (32) Wbemads.dll, aka a variant of the "COM Object Instantiation Memory Corruption vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:11.470-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:01:16.336-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Win2K or XP,SP1 is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criteria operator="OR" comment="a vulnerable version of mshtml.dll exists GDR/QFE">
          <criterion comment="machine has followed the GDR update path and mshtml.dll is less than 6.0.2800.1522" negate="false" test_ref="oval:org.mitre.oval:tst:871"/>
          <criterion comment="machine has followed the QFE update path and mshtml.dll is less than 6.0.2800.1523" negate="false" test_ref="oval:org.mitre.oval:tst:870"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1536" version="5" class="vulnerability">
      <metadata>
        <title>CSNW Remote Buffer Overflow via Network Messages (Win2k,SP4)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>NetWare</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1985" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1985"/>
        <description>The Client Service for NetWare (CSNW) on Microsoft Windows 2000 SP4, XP SP1 and Sp2, and Server 2003 SP1 and earlier, allows remote attackers to execute arbitrary code due to an "unchecked buffer" when processing certain crafted network messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-31T12:00:00.000-04:00" comment="removed an incorrect leading ^ from the value entity of ste:2402">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-31T00:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:20.941-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:12.497-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:01:15.712-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="Win2K/XP/2003 service pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2569"/>
        <criterion comment="nwwks.dll is less than 5.0.2195.7065" negate="false" test_ref="oval:org.mitre.oval:tst:873"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1535" version="5" class="vulnerability">
      <metadata>
        <title>Win2k,SP4 DDS Library Shape Control Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2127" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2127"/>
        <description>Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, as originally demonstrated using the (1) DDS Library Shape Control (Msdds.dll) COM object, and other objects including (2) Blnmgrps.dll, (3) Ciodm.dll, (4) Comsvcs.dll, (5) Danim.dll, (6) Htmlmarq.ocx, (7) Mdt2dd.dll (as demonstrated using a heap corruption attack with uninitialized memory), (8) Mdt2qd.dll, (9) Mpg4ds32.ax, (10) Msadds32.ax, (11) Msb1esen.dll, (12) Msb1fren.dll, (13) Msb1geen.dll, (14) Msdtctm.dll, (15) Mshtml.dll, (16) Msoeacct.dll, (17) Msosvfbr.dll, (18) Mswcrun.dll, (19) Netshell.dll, (20) Ole2disp.dll, (21) Outllib.dll, (22) Psisdecd.dll, (23) Qdvd.dll, (24) Repodbc.dll, (25) Shdocvw.dll, (26) Shell32.dll, (27) Soa.dll, (28) Srchui.dll, (29) Stobject.dll, (30) Vdt70.dll, (31) Vmhelper.dll, and (32) Wbemads.dll, aka a variant of the "COM Object Instantiation Memory Corruption vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-31T12:00:00.000-04:00" comment="removed an incorrect leading ^ from the value entity of ste:2402">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-31T00:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:20.767-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:13.440-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:01:15.424-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="Win2K/XP/2003 service pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2569"/>
        <criterion comment="mshtml.dll is less than 5.0.3833.200" negate="false" test_ref="oval:org.mitre.oval:tst:874"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1525" version="1" class="vulnerability">
      <metadata>
        <title>Excel Viewer 2003 Remote Code Execution via Malformed Record</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Office</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0031" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0031"/>
        <description>Stack-based buffer overflow in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed record with a modified length value, which leads to memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-15T10:53:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-15T07:17:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Xlview.exe is installed with a version less than 11.0.8012.0" negate="false" test_ref="oval:org.mitre.oval:tst:881"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1523" version="10" class="vulnerability">
      <metadata>
        <title>Unsupported Version of Windows</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
        </affected>
        <reference source="MISC" ref_id="http://support.microsoft.com/default.aspx?scid=fh;EN-US;sp" ref_url="http://support.microsoft.com/default.aspx?scid=fh;EN-US;sp"/>
        <description>'As Service Packs released by Microsoft mature, earlier versions and releases become unsupported. This equates to a cessation in software and security patches for that baseline. Using an unsupported version of Windows represents a severe security risk.'</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Removed unneeded ste:2282 from tst:2437. Deprecated ste:2282 since it is no longer used." date="2007-01-12T07:06:00.595-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-01-12T07:08:59.774-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:49.040-05:00">ACCEPTED</status_change>
            <modified comment="Fixed regex in ste:2889.  Implemented by Matthew Wojcik." date="2007-03-06T18:19:00.507-05:00">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2007-03-06T18:21:09.389-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:16:52.430-04:00">ACCEPTED</status_change>
            <modified comment="Corrected url to reference. Implemented by Jon Baker of The MITRE Corporation." date="2007-05-07T11:51:00.078-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-05-07T11:52:59.131-04:00">INTERIM</status_change>
            <status_change date="2007-05-23T15:05:28.970-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1523 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:06:21.263-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:01:13.693-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1523 - Typo corrections" date="2014-05-23T10:35:00.266-04:00">
              <contributor organization="McAfee, Inc.">Jerome Athias</contributor>
            </modified>
            <status_change date="2014-05-23T10:37:26.513-04:00">INTERIM</status_change>
            <status_change date="2014-06-09T04:00:13.420-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="An unsupported version of Windows XP is installed">
          <criterion comment="Windows XP is installed" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion negate="true" comment="Win2K/XP/2003 is patched" test_ref="oval:org.mitre.oval:tst:2437"/>
        </criteria>
        <criteria operator="AND" comment="Windows 2000 (sp3 or earlier) is installed">
          <criterion comment="Windows 2000 is installed" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion negate="true" comment="Win2K/XP/2003 service pack 4 (or later) is installed" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1521" version="8" class="vulnerability">
      <metadata>
        <title>Win2K,SP4 HTTPS Proxy Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2830" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2830"/>
        <description>Microsoft Internet Explorer 5.01, 5.5, and 6, when using an HTTPS proxy server that requires Basic Authentication, sends URLs in cleartext, which allows remote attackers to obtain sensitive information, aka "HTTPS Proxy Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-12-13T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-16T01:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed ste:2614: set datatype to version.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:54:00.319-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:59:40.749-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:48.781-05:00">ACCEPTED</status_change>
            <modified comment="Fixed regex in ste:2889.  Implemented by Matthew Wojcik." date="2007-03-06T18:19:00.507-05:00">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2007-03-06T18:21:06.763-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:16:52.152-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:04.389-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:01:13.356-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:33.261-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:19.447-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3835.2200" negate="false" test_ref="oval:org.mitre.oval:tst:893"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1512" version="3" class="vulnerability">
      <metadata>
        <title>Windows Virtual DOS Machine Local Privilege Escalation Vulnerability (Test 1)</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>VDM</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0118" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0118"/>
        <description>The component for the Virtual DOS Machine (VDM) subsystem in Windows NT 4.0 and Windows 2000 does not properly validate system structures, which allows local users to access protected kernel memory and execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-11T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <modified date="2004-07-19T12:00:00.000-04:00" comment="Modifed without comment">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2004-08-04T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added Microsoft Windows 2000 to the affected platforms. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-22T19:58:00.242-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-22T19:57:17.267-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:48.100-05:00">ACCEPTED</status_change>
            <modified comment="Removed reference to test for nt 4.0 and add reference to nt 4.0 inventory definition." date="2008-02-28T12:48:00.621-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2008-03-03T04:00:34.519-05:00">INTERIM</status_change>
            <status_change date="2008-03-24T04:00:15.992-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Software section">
        <criterion comment="The version of Ntoskrnl.exe is less than 5.0.2195.6902" test_ref="oval:org.mitre.oval:tst:885"/>
        <criterion negate="true" comment="the patch kb835732 is installed" test_ref="oval:org.mitre.oval:tst:1510"/>
        <criteria operator="OR" comment="Windows NT or 2000 Installed">
          <extend_definition comment="Microsoft Windows NT is installed" definition_ref="oval:org.mitre.oval:def:36"/>
          <criterion comment="Windows 2000 is installed" test_ref="oval:org.mitre.oval:tst:3085"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1505" version="7" class="vulnerability">
      <metadata>
        <title>Win2K/XP,SP1 File Download Dialog Box Manipulation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2829" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2829"/>
        <description>Multiple design errors in Microsoft Internet Explorer 5.01, 5.5, and 6 allow user-assisted attackers to execute arbitrary code by (1) overlaying a malicious new window above a file download box, then (2) using a keyboard shortcut and delaying the display of the file download box until the user hits a shortcut that activates the "Run" button, aka "File Download Dialog Box Manipulation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-12-13T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-16T01:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:45:57.463-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:47.043-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:33.797-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:01:09.627-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:42.038-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:18.348-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Win2K or XP,SP1 is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2800.1528" negate="false" test_ref="oval:org.mitre.oval:tst:2390"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1503" version="2" class="vulnerability">
      <metadata>
        <title>Windows 2000 HtmlHelp Heap Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>HTML Help Facility</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0201" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0201"/>
        <description>Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerability than CVE-2003-1041.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-08-04T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected obj:964. Changed registry key name from a pattern match of .* to nil." date="2007-02-12T13:46:00.470-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-12T13:47:37.659-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:16:51.623-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="the version of itss.dll is less than 5.2.3790.185" negate="false" test_ref="oval:org.mitre.oval:tst:1406"/>
          <criterion comment="the patch kb840315 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1405"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="HTML Help is registered" negate="true" test_ref="oval:org.mitre.oval:tst:1404"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1497" version="2" deprecated="true" class="vulnerability">
      <metadata>
        <title>Mozilla Application Suite has reached End-of-Life</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="MISC" ref_id="http://www.mozilla.org/projects/seamonkey/"/>
        <description>'mozilla.org has launched and delivered SeaMonkey, a community effort to deliver production-quality releases of code derived from the \"Mozilla Application Suite\".  This equates to a cessation in software and security patches for that baseline.  Using an unsupported software represents a high security risk because no fixes or patches will be made available in response to new vulnerabilities.'</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-07T06:13:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-22T08:27:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Removed reference to ste:2286 and deprectated ste:2286" date="2007-02-12T10:30:00.540-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-12T10:32:01.704-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:2285" date="2007-03-06T08:03:00.800-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:51.349-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:1386" date="2007-04-23T12:05:00.444-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-07T12:23:25.957-04:00">INTERIM</status_change>
            <modified comment="Deprected because Mozilla Suite has not reached end of life. Implemented by Jon Baker of The MITRE Corporation." date="2007-05-07T12:05:00.444-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-05-07T12:23:25.957-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Suite is installed">
          <criterion comment="Mozilla Suite installed" negate="false" test_ref="oval:org.mitre.oval:tst:2441"/>
          <criterion comment="Mozilla Suite is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2440"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1490" version="8" class="vulnerability">
      <metadata>
        <title>Win2K,SP4 File Download Dialog Box Manipulation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2829" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2829"/>
        <description>Multiple design errors in Microsoft Internet Explorer 5.01, 5.5, and 6 allow user-assisted attackers to execute arbitrary code by (1) overlaying a malicious new window above a file download box, then (2) using a keyboard shortcut and delaying the display of the file download box until the user hits a shortcut that activates the "Run" button, aka "File Download Dialog Box Manipulation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-12-13T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-16T01:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed ste:2614: set datatype to version.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:54:00.319-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:59:46.384-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:46.431-05:00">ACCEPTED</status_change>
            <modified comment="Fixed regex in ste:2889.  Implemented by Matthew Wojcik." date="2007-03-06T18:19:00.507-05:00">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2007-03-06T18:21:16.136-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:16:50.508-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:46:06.953-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:01:07.867-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:53.270-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:18.180-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3835.2200" negate="false" test_ref="oval:org.mitre.oval:tst:893"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1489" version="8" class="vulnerability">
      <metadata>
        <title>Win2k,SP4 IE Mismatched Document Object Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1790" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1790"/>
        <description>Microsoft Internet Explorer 6 SP2 6.0.2900.2180 and 6.0.2800.1106, and earlier versions, allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a Javascript BODY onload event that calls the window function, aka "Mismatched Document Object Model Objects Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-11T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-12T10:00:00.000-04:00">DRAFT</status_change>
            <modified date="2005-12-14T12:00:00.000-04:00" comment="Updated with newly available information.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed ste:2614: set datatype to version.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:54:00.319-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:59:45.552-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:46.220-05:00">ACCEPTED</status_change>
            <modified comment="Fixed regex in ste:2889.  Implemented by Matthew Wojcik." date="2007-03-06T18:19:00.507-05:00">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2007-03-06T18:21:11.224-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:16:50.216-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:59.985-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:01:07.495-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:51.396-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:17.981-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3835.2200" negate="false" test_ref="oval:org.mitre.oval:tst:893"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1488" version="6" class="vulnerability">
      <metadata>
        <title>.lnk File-Open Remote Code Execution Vulnerability (Windows 2000,SP4)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2122" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2122"/>
        <description>Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to execute arbitrary commands via a shortcut (.lnk) file with long font properties that lead to a buffer overflow in the Client/Server Runtime Server Subsystem (CSRSS), a different vulnerability than CVE-2005-2118.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-31T12:00:00.000-04:00" comment="removed an incorrect leading ^ from the value entity of ste:2402">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-31T00:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:19.681-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1488 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:04:53.514-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:01:07.188-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Windows 2000 is installed" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="Win2K/XP/2003 service pack 4 is installed" test_ref="oval:org.mitre.oval:tst:2569"/>
        <criterion comment="shell32.dll is less than 5.0.3900.7071" test_ref="oval:org.mitre.oval:tst:1086"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:14842" version="4" class="vulnerability" deprecated="true">
      <metadata>
        <title>DEPRECATED: Integer signedness error in the db2dasrrm process in the DB2 Administration Server (DAS) in IBM DB2 9.1 through FP11, 9.5 before FP9, and 9.7 through FP5 on UNIX platforms allows remote attackers to execute arbitrary code via a crafted request that triggers a heap-based buffer overflow.</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>IBM DB2 UDB</product>
        </affected>
        <reference ref_id="CVE-2012-0711" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0711" source="CVE"/>
        <description>Integer signedness error in the db2dasrrm process in the DB2 Administration Server (DAS) in IBM DB2 9.1 through FP11, 9.5 before FP9, and 9.7 through FP5 on UNIX platforms allows remote attackers to execute arbitrary code via a crafted request that triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2012-03-26T11:21:43.000-05:00">
              <contributor organization="DTCC">Scott Quint</contributor>
            </submitted>
            <status_change date="2012-03-27T14:24:42.994-04:00">DRAFT</status_change>
            <status_change date="2012-04-16T04:06:04.211-04:00">INTERIM</status_change>
            <status_change date="2012-05-07T04:00:34.220-04:00">ACCEPTED</status_change>
            <modified comment="Title indicates UNIX but Win platform defined" date="2013-07-26T14:29:45.664-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T14:29:45.664-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Determine if the version of IBM DB2 UDB is less than or equal to 9.7 and is greater than or equal to 9.1">
          <extend_definition comment="IBM DB2 UDB is installed" definition_ref="oval:org.mitre.oval:def:12505"/>
          <criterion comment="Determine if the version of IBM DB2 UDB is less than or equal to 9.7" test_ref="oval:org.mitre.oval:tst:77686"/>
          <criterion comment="Determine if the version of IBM DB2 UDB is greater than or equal to 9.1" test_ref="oval:org.mitre.oval:tst:77532"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:14826" version="3" class="vulnerability">
      <metadata>
        <title>XSS in wizardlist.aspx Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft SharePoint Server 2010</product>
          <product>Microsoft SharePoint Foundation 2010</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2012-0145" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0145"/>
        <description>Cross-site scripting (XSS) vulnerability in wizardlist.aspx in Microsoft Office SharePoint Server 2010 Gold and SP1 and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via JavaScript sequences in a URL, aka "XSS in wizardlist.aspx Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2012-02-14T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2012-02-21T12:28:22.834-05:00">DRAFT</status_change>
            <status_change date="2012-03-12T04:00:29.462-04:00">INTERIM</status_change>
            <status_change date="2012-04-02T04:00:22.963-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Vulnerable Microsoft Office SharePoint Server 2010">
          <extend_definition comment="Microsoft Office SharePoint Server 2010 is installed." definition_ref="oval:org.mitre.oval:def:12880"/>
          <criterion comment="Microsoft.SharePoint.Taxonomy.dll version is less than 14.0.6113.5000" test_ref="oval:org.mitre.oval:tst:78074"/>
        </criteria>
        <criteria comment="Vulnerable Microsoft SharePoint Foundation 2010">
          <extend_definition comment="Microsoft SharePoint Foundation 2010 is installed" definition_ref="oval:org.mitre.oval:def:12224"/>
          <criterion comment="OWSSVR.DLL version is less than 14.0.6114.5001" test_ref="oval:org.mitre.oval:tst:77961"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:14822" version="7" class="vulnerability">
      <metadata>
        <title>Buffer overflow in kpprzrdr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted .prz attachment.  NOTE: some of these details are obtained from third party information.</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Lotus Notes</product>
        </affected>
        <reference ref_id="CVE-2011-1217" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1217" source="CVE"/>
        <description>Buffer overflow in kpprzrdr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted .prz attachment.  NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-12-16T09:51:51.000-05:00">
              <contributor organization="DTCC">Scott Quint</contributor>
            </submitted>
            <status_change date="2011-12-19T15:44:17.088-05:00">DRAFT</status_change>
            <status_change date="2012-01-09T04:00:40.739-05:00">INTERIM</status_change>
            <status_change date="2012-01-30T04:00:54.547-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.altx-soft.oval:ste:18430 - contains tests with modified comments and all dependences" date="2014-02-13T12:19:00.287-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:22:40.813-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:00:47.396-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:14822 - registry_tests replaced with file_tests because registry path was compared with version" date="2015-05-29T11:02:00.629-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-05-29T11:05:02.806-04:00">INTERIM</status_change>
            <status_change date="2015-06-15T04:00:10.166-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Determine if the version of Lotus Notes is less than or equal to 8.5.2.2 and is greater than or equal to 8.0.0">
          <extend_definition comment="IBM Lotus Notes is installed" definition_ref="oval:org.mitre.oval:def:11999"/>
          <criterion comment="Determine if the version of Lotus Notes is less than or equal to 8.5.2.2" test_ref="oval:org.mitre.oval:tst:138913"/>
          <criterion comment="Determine if the version of Lotus Notes is greater than or equal to 8.0.0" test_ref="oval:org.mitre.oval:tst:138507"/>
        </criteria>
        <criteria operator="AND" comment="Determine if the version of Lotus Notes is less than or equal to 7.0.4 and is greater than or equal to 7.0.0">
          <extend_definition comment="IBM Lotus Notes is installed" definition_ref="oval:org.mitre.oval:def:11999"/>
          <criterion comment="Determine if the version of Lotus Notes is less than or equal to 7.0.4" test_ref="oval:org.mitre.oval:tst:138653"/>
          <criterion comment="Determine if the version of Lotus Notes is greater than or equal to 7.0.0" test_ref="oval:org.mitre.oval:tst:138900"/>
        </criteria>
        <criteria operator="AND" comment="Determine if the version of Lotus Notes is less than or equal to 6.5.6 and is greater than or equal to 6.0.1">
          <extend_definition comment="IBM Lotus Notes is installed" definition_ref="oval:org.mitre.oval:def:11999"/>
          <criterion comment="Determine if the version of Lotus Notes is less than or equal to 6.5.6" test_ref="oval:org.mitre.oval:tst:138776"/>
          <criterion comment="Determine if the version of Lotus Notes is greater than or equal to 6.0.1" test_ref="oval:org.mitre.oval:tst:138813"/>
        </criteria>
        <criteria operator="AND" comment="Determine if the version of Lotus Notes is less than or equal to 5.2 and is greater than or equal to 5:0a">
          <extend_definition comment="IBM Lotus Notes is installed" definition_ref="oval:org.mitre.oval:def:11999"/>
          <criterion comment="Determine if the version of Lotus Notes is less than or equal to 5.2" test_ref="oval:org.mitre.oval:tst:138910"/>
          <criterion comment="Determine if the version of Lotus Notes is greater than or equal to 5:0a" test_ref="oval:org.mitre.oval:tst:138741"/>
        </criteria>
        <criteria operator="AND" comment="Determine if the version of Lotus Notes is less than or equal to 4.6 and is greater than or equal to 4.2.1">
          <extend_definition comment="IBM Lotus Notes is installed" definition_ref="oval:org.mitre.oval:def:11999"/>
          <criterion comment="Determine if the version of Lotus Notes is less than or equal to 4.6" test_ref="oval:org.mitre.oval:tst:138685"/>
          <criterion comment="Determine if the version of Lotus Notes is greater than or equal to 4.2.1" test_ref="oval:org.mitre.oval:tst:138657"/>
        </criteria>
        <criteria operator="AND" comment="Determine if the version of Lotus Notes is less than or equal to 3.0.0.2 and is greater than or equal to 3.0.0.1">
          <extend_definition comment="IBM Lotus Notes is installed" definition_ref="oval:org.mitre.oval:def:11999"/>
          <criterion comment="Determine if the version of Lotus Notes is less than or equal to 3.0.0.2" test_ref="oval:org.mitre.oval:tst:138223"/>
          <criterion comment="Determine if the version of Lotus Notes is greater than or equal to 3.0.0.1" test_ref="oval:org.mitre.oval:tst:138612"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1480" version="3" class="vulnerability">
      <metadata>
        <title>Heap Overrun in XBM Image Processing</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2701" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2701"/>
        <description>Heap-based buffer overflow in Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to execute arbitrary code via an XBM image file that ends in a large number of spaces instead of the expected end tag.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-11T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-12T10:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:2367" date="2007-02-26T08:32:00.241-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-26T08:32:38.207-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:2370" date="2007-03-06T07:46:00.064-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:49.989-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:1444" date="2007-04-23T12:05:00.911-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:19:58.245-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:1445" date="2007-04-23T12:05:00.720-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:10:54.113-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Suite version 1.7.10 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.10 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2535"/>
          <criterion comment="Mozilla Suite version 1.7.10 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2534"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.6 or earlier is installed">
          <criterion comment="Firefox version 1.0.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2533"/>
          <criterion comment="Mozilla Firefox version 1.0.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2532"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:14752" version="7" class="vulnerability">
      <metadata>
        <title>SSL and TLS Protocols Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2011-3389" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3389"/>
        <description>The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a "BEAST" attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2012-01-10T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2012-01-13T18:21:49.230-05:00">DRAFT</status_change>
            <status_change date="2012-01-30T04:00:50.643-05:00">INTERIM</status_change>
            <status_change date="2012-02-20T04:00:05.870-05:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:00.587-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:00.587-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:02:49.182-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:12547 - Submission on Microsoft Bulletin for the month April 2013." date="2013-04-15T21:59:00.487-04:00">
              <contributor organization="SecPod Technologies">Sharath S</contributor>
            </modified>
            <status_change date="2013-04-15T22:08:43.714-04:00">INTERIM</status_change>
            <status_change date="2013-05-06T04:01:18.655-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP SP3 x86">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of schannel.dll is less than 5.1.2600.6175" test_ref="oval:org.mitre.oval:tst:78080"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP SP2 x64, Windows Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR" comment="Microsoft Windows XP SP2 x64, Windows Server 2003 x86/x64/ia64 SP2">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of schannel.dll is less than 5.2.3790.4935" test_ref="oval:org.mitre.oval:tst:77784"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 SP2, Server 2008 x86/x64/ia64 SP2">
          <criteria operator="OR" comment="Microsoft Windows Vista x86/x64 SP2, Server 2008 x86/x64/ia64 SP2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of schannel.dll is less than 6.0.6002.18541" test_ref="oval:org.mitre.oval:tst:77820"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of schannel.dll is greater than or equal to 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:41611"/>
              <criterion comment="the version of schannel.dll is less than 6.0.6002.22742" test_ref="oval:org.mitre.oval:tst:77927"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x64/ia64">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of schannel.dll is less than 6.1.7600.16915" test_ref="oval:org.mitre.oval:tst:78013"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of schannel.dll is greater than or equal to 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:41670"/>
              <criterion comment="the version of schannel.dll is less than 6.1.7600.21092" test_ref="oval:org.mitre.oval:tst:78070"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64 SP1, Windows Server 2008 R2 x64/ia64 SP1">
          <criteria operator="OR" comment="Microsoft Windows 7 x86/x64 SP1, Windows Server 2008 R2 x64/ia64 SP1">
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="the version of schannel.dll is less than 6.1.7601.17725" test_ref="oval:org.mitre.oval:tst:77990"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="the version of schannel.dll is greater than or equal to 6.1.7601.21000" test_ref="oval:org.mitre.oval:tst:78054"/>
              <criterion comment="the version of schannel.dll is less than 6.1.7601.21861" test_ref="oval:org.mitre.oval:tst:77974"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12627" version="10" class="inventory">
      <metadata>
        <title>Microsoft Windows 7 x64 Service Pack 1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_7::sp1:x64"/>
        <description>The operating system installed on the system is Microsoft Windows 7 x64 Service Pack 1</description>
        <oval_repository>
          <dates>
            <submitted date="2011-02-23T11:42:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </submitted>
            <status_change date="2011-02-28T09:34:48.913-05:00">DRAFT</status_change>
            <status_change date="2011-03-21T04:00:13.798-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:12087 - Modified pattern match for ste:12087." date="2011-03-29T13:23:00.865-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2011-04-18T04:00:32.009-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:12087 - Updated comment for ste:12087" date="2011-05-04T09:09:00.463-04:00">
              <contributor organization="Secure Elements, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2011-05-04T09:14:35.542-04:00">INTERIM</status_change>
            <status_change date="2011-05-23T04:00:15.251-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:3180 - new inventory for SQL Server 2008 R2 64-bit" date="2013-07-05T09:33:00.078-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-05T09:37:53.419-04:00">INTERIM</status_change>
            <status_change date="2013-07-22T04:00:09.204-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5027 - removed extraneous whitespace from regex" date="2015-05-21T13:26:00.569-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-05-21T13:29:02.486-04:00">INTERIM</status_change>
            <status_change date="2015-06-08T04:00:07.949-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criterion comment="Windows 7 is installed" test_ref="oval:org.mitre.oval:tst:10792"/>
        <criterion comment="a version of Windows for the x64 architecture is installed" test_ref="oval:org.mitre.oval:tst:3653"/>
        <criterion comment="Service Pack 1 is installed" test_ref="oval:org.mitre.oval:tst:41933"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12583" version="8" class="inventory">
      <metadata>
        <title>Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium"/>
        <description>The operating system installed on the system is Microsoft Windows Server 2008 R2 Itanium Edition Service Pack 1</description>
        <oval_repository>
          <dates>
            <submitted date="2011-03-08T14:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2011-03-08T13:52:14.351-05:00">DRAFT</status_change>
            <status_change date="2011-03-28T04:00:09.481-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:12087 - Modified pattern match for ste:12087." date="2011-03-29T13:23:00.865-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2011-04-18T04:00:29.145-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:12087 - Updated comment for ste:12087" date="2011-05-04T09:09:00.463-04:00">
              <contributor organization="Secure Elements, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2011-05-04T09:14:35.800-04:00">INTERIM</status_change>
            <status_change date="2011-05-23T04:00:14.534-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:10.087-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:10.087-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:02:12.279-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criterion comment="Windows Server 2008 R2 is installed" test_ref="oval:org.mitre.oval:tst:10317"/>
        <criterion comment="a version of Windows for the ia64 architecture is installed" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="Service Pack 1 is installed" test_ref="oval:org.mitre.oval:tst:41933"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12567" version="10" class="inventory">
      <metadata>
        <title>Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_server_2008:r2:sp1:x64"/>
        <description>The operating system installed on the system is Microsoft Windows Server 2008 R2 x64 Service Pack 1</description>
        <oval_repository>
          <dates>
            <submitted date="2011-03-08T14:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2011-03-08T13:52:14.186-05:00">DRAFT</status_change>
            <status_change date="2011-03-28T04:00:09.125-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:12087 - Modified pattern match for ste:12087." date="2011-03-29T13:23:00.865-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2011-04-18T04:00:28.076-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:12087 - Updated comment for ste:12087" date="2011-05-04T09:09:00.463-04:00">
              <contributor organization="Secure Elements, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2011-05-04T09:14:36.142-04:00">INTERIM</status_change>
            <status_change date="2011-05-23T04:00:13.850-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:10.103-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:10.103-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:02:10.076-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:3180 - new inventory for SQL Server 2008 R2 64-bit" date="2013-07-05T09:33:00.078-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-05T09:37:56.866-04:00">INTERIM</status_change>
            <status_change date="2013-07-22T04:00:08.743-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criterion comment="Windows Server 2008 R2 is installed" test_ref="oval:org.mitre.oval:tst:10317"/>
        <criterion comment="a version of Windows for the x64 architecture is installed" test_ref="oval:org.mitre.oval:tst:3653"/>
        <criterion comment="Service Pack 1 is installed" test_ref="oval:org.mitre.oval:tst:41933"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12292" version="8" class="inventory">
      <metadata>
        <title>Microsoft Windows 7 (32-bit) Service Pack 1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_7::sp1:x86"/>
        <description>The operating system installed on the system is Microsoft Windows 7 (32-bit) Service Pack 1</description>
        <oval_repository>
          <dates>
            <submitted date="2011-02-23T11:42:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </submitted>
            <status_change date="2011-02-28T09:34:48.696-05:00">DRAFT</status_change>
            <status_change date="2011-03-21T04:00:07.252-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:12087 - Modified pattern match for ste:12087." date="2011-03-29T13:23:00.865-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2011-04-18T04:00:16.014-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:12087 - Updated comment for ste:12087" date="2011-05-04T09:09:00.463-04:00">
              <contributor organization="Secure Elements, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2011-05-04T09:14:35.212-04:00">INTERIM</status_change>
            <status_change date="2011-05-23T04:00:09.781-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5027 - removed extraneous whitespace from regex" date="2015-05-21T13:26:00.569-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-05-21T13:29:02.409-04:00">INTERIM</status_change>
            <status_change date="2015-06-08T04:00:04.456-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criterion comment="Windows 7 is installed" test_ref="oval:org.mitre.oval:tst:10792"/>
        <criterion comment="a version of Windows for the x86 architecture is installed" test_ref="oval:org.mitre.oval:tst:3823"/>
        <criterion comment="Service Pack 1 is installed" test_ref="oval:org.mitre.oval:tst:41933"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:14725" version="5" class="vulnerability">
      <metadata>
        <title>IBM Lotus Notes 7.0, 8.0, and 8.5 stores administrative credentials in cleartext in SURunAs.exe, which allows local users to obtain sensitive information by examining this file, aka SPR JSTN837SEG.</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Lotus Notes</product>
        </affected>
        <reference ref_id="CVE-2010-1487" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1487" source="CVE"/>
        <description>IBM Lotus Notes 7.0, 8.0, and 8.5 stores administrative credentials in cleartext in SURunAs.exe, which allows local users to obtain sensitive information by examining this file, aka SPR JSTN837SEG.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-12-16T09:51:32.000-05:00">
              <contributor organization="DTCC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2011-12-19T15:44:07.703-05:00">DRAFT</status_change>
            <status_change date="2012-01-09T04:00:35.879-05:00">INTERIM</status_change>
            <status_change date="2012-01-30T04:00:48.476-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:14725 - registry_tests replaced with file_tests because registry path was compared with version" date="2015-05-29T11:02:00.629-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-05-29T11:05:01.415-04:00">INTERIM</status_change>
            <status_change date="2015-06-15T04:00:09.976-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Determine if the version of Lotus Notes is equal to 7.0">
          <extend_definition comment="IBM Lotus Notes is installed" definition_ref="oval:org.mitre.oval:def:11999"/>
          <criterion comment="Determine if the version of Lotus Notes is equal to 7.0" test_ref="oval:org.mitre.oval:tst:138810"/>
        </criteria>
        <criteria operator="AND" comment="Determine if the version of Lotus Notes is less than or equal to 8.5 and is greater than or equal to 8.0">
          <extend_definition comment="IBM Lotus Notes is installed" definition_ref="oval:org.mitre.oval:def:11999"/>
          <criterion comment="Determine if the version of Lotus Notes is less than or equal to 8.5" test_ref="oval:org.mitre.oval:tst:138551"/>
          <criterion comment="Determine if the version of Lotus Notes is greater than or equal to 8.0" test_ref="oval:org.mitre.oval:tst:138897"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:14720" version="4" class="vulnerability" deprecated="true">
      <metadata>
        <title>DEPRECATED: Unspecified vulnerability in IBM DB2 9.7 before FP5 on UNIX, when the Self Tuning Memory Manager (STMM) feature and the AUTOMATIC DATABASE_MEMORY setting are configured, allows local users to cause a denial of service (daemon crash) via unknown vectors.</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>IBM DB2 UDB</product>
        </affected>
        <reference ref_id="CVE-2011-1373" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1373" source="CVE"/>
        <description>Unspecified vulnerability in IBM DB2 9.7 before FP5 on UNIX, when the Self Tuning Memory Manager (STMM) feature and the AUTOMATIC DATABASE_MEMORY setting are configured, allows local users to cause a denial of service (daemon crash) via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-12-16T09:51:56.000-05:00">
              <contributor organization="DTCC">Scott Quint</contributor>
            </submitted>
            <status_change date="2011-12-19T15:44:08.693-05:00">DRAFT</status_change>
            <status_change date="2012-01-09T04:00:35.597-05:00">INTERIM</status_change>
            <status_change date="2012-01-30T04:00:48.168-05:00">ACCEPTED</status_change>
            <modified comment="Title indicates UNIX but Win platform defined" date="2013-07-26T13:52:39.416-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T13:52:39.416-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Determine if the version of IBM DB2 UDB is less than or equal to 9.7.0.4 and is greater than or equal to 9.7.0.1">
          <extend_definition comment="IBM DB2 UDB is installed" definition_ref="oval:org.mitre.oval:def:12505"/>
          <criterion comment="Determine if the version of IBM DB2 UDB is less than or equal to 9.7.0.4" test_ref="oval:org.mitre.oval:tst:77830"/>
          <criterion comment="Determine if the version of IBM DB2 UDB is greater than or equal to 9.7.0.1" test_ref="oval:org.mitre.oval:tst:77780"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:147" version="5" class="vulnerability">
      <metadata>
        <title>Windows 2000 Shell Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows Shell</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0070" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0070"/>
        <description>Buffer overflow in Windows Shell (used as the Windows Desktop) allows local and possibly remote attackers to execute arbitrary code via a custom URL handler that has not been removed for an application that has been improperly uninstalled.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <modified date="2005-09-26T10:58:00.000-04:00" comment="modified wft-244 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed regex in ste:2889.  Implemented by Matthew Wojcik." date="2007-03-06T18:19:00.507-05:00">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2007-03-06T18:21:12.901-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:16:49.543-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:31.269-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:01:05.213-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 (sp3 or earlier) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="the version of shell32.dll is less than 5.0.3502.4718" negate="false" test_ref="oval:org.mitre.oval:tst:2878"/>
        <criterion comment="Patch Q313829 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3087"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:14650" version="5" class="vulnerability">
      <metadata>
        <title>Stack-based buffer overflow in mw8sr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted link in a Microsoft Office document attachment, aka SPR PRAD8823ND.</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Lotus Notes</product>
        </affected>
        <reference ref_id="CVE-2011-1215" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1215" source="CVE"/>
        <description>Stack-based buffer overflow in mw8sr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted link in a Microsoft Office document attachment, aka SPR PRAD8823ND.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-12-16T09:51:48.000-05:00">
              <contributor organization="DTCC">Scott Quint</contributor>
            </submitted>
            <status_change date="2011-12-19T15:44:08.907-05:00">DRAFT</status_change>
            <status_change date="2012-01-09T04:00:30.961-05:00">INTERIM</status_change>
            <status_change date="2012-01-30T04:00:43.467-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:14650 - registry_tests replaced with file_tests because registry path was compared with version" date="2015-05-29T11:02:00.629-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-05-29T11:05:02.530-04:00">INTERIM</status_change>
            <status_change date="2015-06-15T04:00:09.753-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Determine if the version of Lotus Notes is less than or equal to 8.5.2.2 and is greater than or equal to 8.0.0">
          <extend_definition comment="IBM Lotus Notes is installed" definition_ref="oval:org.mitre.oval:def:11999"/>
          <criterion comment="Determine if the version of Lotus Notes is less than or equal to 8.5.2.2" test_ref="oval:org.mitre.oval:tst:138913"/>
          <criterion comment="Determine if the version of Lotus Notes is greater than or equal to 8.0.0" test_ref="oval:org.mitre.oval:tst:138507"/>
        </criteria>
        <criteria operator="AND" comment="Determine if the version of Lotus Notes is less than or equal to 7.0.4 and is greater than or equal to 7.0.0">
          <extend_definition comment="IBM Lotus Notes is installed" definition_ref="oval:org.mitre.oval:def:11999"/>
          <criterion comment="Determine if the version of Lotus Notes is less than or equal to 7.0.4" test_ref="oval:org.mitre.oval:tst:138653"/>
          <criterion comment="Determine if the version of Lotus Notes is greater than or equal to 7.0.0" test_ref="oval:org.mitre.oval:tst:138900"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:14637" version="3" class="vulnerability">
      <metadata>
        <title>XSS in inplview.aspx Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft SharePoint Foundation 2010</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2012-0017" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0017"/>
        <description>Cross-site scripting (XSS) vulnerability in inplview.aspx in Microsoft SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via JavaScript sequences in a URL, aka "XSS in inplview.aspx Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2012-02-14T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2012-02-21T12:28:22.209-05:00">DRAFT</status_change>
            <status_change date="2012-03-12T04:00:21.224-04:00">INTERIM</status_change>
            <status_change date="2012-04-02T04:00:15.016-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft SharePoint Foundation 2010 is installed" definition_ref="oval:org.mitre.oval:def:12224"/>
        <criterion comment="OWSSVR.DLL version is less than 14.0.6114.5001" test_ref="oval:org.mitre.oval:tst:77961"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:14634" version="7" class="vulnerability">
      <metadata>
        <title>Integer underflow in lzhsr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted header in a .lzh attachment that triggers a stack-based buffer overflow, aka SPR PRAD88MJ2W.</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Lotus Notes</product>
        </affected>
        <reference ref_id="CVE-2011-1213" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1213" source="CVE"/>
        <description>Integer underflow in lzhsr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted header in a .lzh attachment that triggers a stack-based buffer overflow, aka SPR PRAD88MJ2W.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-12-16T09:51:42.000-05:00">
              <contributor organization="DTCC">Scott Quint</contributor>
            </submitted>
            <status_change date="2011-12-19T15:44:15.775-05:00">DRAFT</status_change>
            <status_change date="2012-01-09T04:00:29.684-05:00">INTERIM</status_change>
            <status_change date="2012-01-30T04:00:42.152-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.altx-soft.oval:ste:18430 - contains tests with modified comments and all dependences" date="2014-02-13T12:19:00.287-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:22:41.346-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:00:45.890-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:14634 - registry_tests replaced with file_tests because registry path was compared with version" date="2015-05-29T11:02:00.629-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-05-29T11:05:01.700-04:00">INTERIM</status_change>
            <status_change date="2015-06-15T04:00:09.460-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Determine if the version of Lotus Notes is less than or equal to 8.5.2.2 and is greater than or equal to 8.0.0">
          <extend_definition comment="IBM Lotus Notes is installed" definition_ref="oval:org.mitre.oval:def:11999"/>
          <criterion comment="Determine if the version of Lotus Notes is less than or equal to 8.5.2.2" test_ref="oval:org.mitre.oval:tst:138913"/>
          <criterion comment="Determine if the version of Lotus Notes is greater than or equal to 8.0.0" test_ref="oval:org.mitre.oval:tst:138507"/>
        </criteria>
        <criteria operator="AND" comment="Determine if the version of Lotus Notes is less than or equal to 7.0.4 and is greater than or equal to 7.0.0">
          <extend_definition comment="IBM Lotus Notes is installed" definition_ref="oval:org.mitre.oval:def:11999"/>
          <criterion comment="Determine if the version of Lotus Notes is less than or equal to 7.0.4" test_ref="oval:org.mitre.oval:tst:138653"/>
          <criterion comment="Determine if the version of Lotus Notes is greater than or equal to 7.0.0" test_ref="oval:org.mitre.oval:tst:138900"/>
        </criteria>
        <criteria operator="AND" comment="Determine if the version of Lotus Notes is less than or equal to 6.5.6 and is greater than or equal to 6.0.1">
          <extend_definition comment="IBM Lotus Notes is installed" definition_ref="oval:org.mitre.oval:def:11999"/>
          <criterion comment="Determine if the version of Lotus Notes is less than or equal to 6.5.6" test_ref="oval:org.mitre.oval:tst:138776"/>
          <criterion comment="Determine if the version of Lotus Notes is greater than or equal to 6.0.1" test_ref="oval:org.mitre.oval:tst:138813"/>
        </criteria>
        <criteria operator="AND" comment="Determine if the version of Lotus Notes is less than or equal to 5.2 and is greater than or equal to 5:0a">
          <extend_definition comment="IBM Lotus Notes is installed" definition_ref="oval:org.mitre.oval:def:11999"/>
          <criterion comment="Determine if the version of Lotus Notes is less than or equal to 5.2" test_ref="oval:org.mitre.oval:tst:138910"/>
          <criterion comment="Determine if the version of Lotus Notes is greater than or equal to 5:0a" test_ref="oval:org.mitre.oval:tst:138741"/>
        </criteria>
        <criteria operator="AND" comment="Determine if the version of Lotus Notes is less than or equal to 4.6 and is greater than or equal to 4.2.1">
          <extend_definition comment="IBM Lotus Notes is installed" definition_ref="oval:org.mitre.oval:def:11999"/>
          <criterion comment="Determine if the version of Lotus Notes is less than or equal to 4.6" test_ref="oval:org.mitre.oval:tst:138685"/>
          <criterion comment="Determine if the version of Lotus Notes is greater than or equal to 4.2.1" test_ref="oval:org.mitre.oval:tst:138657"/>
        </criteria>
        <criteria operator="AND" comment="Determine if the version of Lotus Notes is less than or equal to 3.0.0.2 and is greater than or equal to 3.0.0.1">
          <extend_definition comment="IBM Lotus Notes is installed" definition_ref="oval:org.mitre.oval:def:11999"/>
          <criterion comment="Determine if the version of Lotus Notes is less than or equal to 3.0.0.2" test_ref="oval:org.mitre.oval:tst:138223"/>
          <criterion comment="Determine if the version of Lotus Notes is greater than or equal to 3.0.0.1" test_ref="oval:org.mitre.oval:tst:138612"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1463" version="3" class="vulnerability">
      <metadata>
        <title>Property Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0945" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0945"/>
        <description>Microsoft Internet Explorer 6 SP1 on Windows 2000 SP4; 6 and 7 on Windows XP SP2, or Windows Server 2003 SP1 or SP2; and 7 on Windows Vista allows remote attackers to execute arbitrary code via certain property methods that may trigger memory corruption, aka "Property Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2007-05-08T19:30:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-05-09T12:53:06-04:00">DRAFT</status_change>
            <status_change date="2007-05-31T15:26:33.666-04:00">INTERIM</status_change>
            <modified comment="Corrected version of ste:3224. Implemented by Jon Baker of the MITRE Corporation." date="2007-06-04T08:42:00.584-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <modified comment="Corrected criteria on 64 bit check" date="2007-06-07T08:42:00.584-04:00">
              <contributor organization="Secure Elements, Inc.">Jeff Ito</contributor>
            </modified>
            <status_change date="2007-06-22T08:57:40.699-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3877 - modified comments" date="2014-02-28T15:13:00.247-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-28T15:16:16.894-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:10.995-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="IE 5.01,SP4 on Win2k,SP4" operator="AND">
          <extend_definition comment="Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Internet Explorer 5.01, SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3850.1900" test_ref="oval:org.mitre.oval:tst:3859"/>
        </criteria>
        <criteria comment="IE 6 on Windows 2000" operator="AND">
          <extend_definition comment="Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1593" test_ref="oval:org.mitre.oval:tst:3454"/>
        </criteria>
        <criteria comment="IE 6 on Windows XP SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1593" test_ref="oval:org.mitre.oval:tst:3454"/>
        </criteria>
        <criteria comment="XP,SP1 (64-bit) and Server 2003, SP1 (IE6)" operator="AND">
          <criteria operator="OR" comment="Windows XP (64-bit,SP1) or Server 2003 (SP1) is installed">
            <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          </criteria>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2885" test_ref="oval:org.mitre.oval:tst:3810"/>
        </criteria>
        <criteria comment="XP,SP2 (64-bit) and Server 2003, SP2 (IE6)" operator="AND">
          <criteria operator="OR" comment="Windows XP (64-bit,SP2) or Server 2003 (SP1) is installed">
            <criteria operator="AND" comment="Windows XP (64-bit,SP2) is installed">
              <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
              <criterion comment="64-Bit version of Windows is installed" test_ref="oval:org.mitre.oval:tst:2744"/>
            </criteria>
            <extend_definition comment="Windows Server 2003, SP2 is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          </criteria>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.4026" test_ref="oval:org.mitre.oval:tst:3176"/>
        </criteria>
        <criteria comment="IE 7 on Windows XP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="the version of Ieapfltr.dll is less than 7.0.6000.16432" test_ref="oval:org.mitre.oval:tst:3877"/>
        </criteria>
        <criteria comment="Windows Server 2003 Service Pack 1 version" operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 (x86) SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of Ieapfltr.dll is less than 7.0.6000.16432" test_ref="oval:org.mitre.oval:tst:3877"/>
        </criteria>
        <criteria comment="Windows Server 2003 Service Pack 2 version" operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <criterion comment="the version of Ieapfltr.dll is less than 7.0.6000.16432" test_ref="oval:org.mitre.oval:tst:3877"/>
        </criteria>
        <criteria comment="IE 7 on Windows Vista" operator="AND">
          <extend_definition comment="Windows Vista is installed" definition_ref="oval:org.mitre.oval:def:228"/>
          <criterion comment="the version of mshtml.dll is less than 7.0.6000.20547" test_ref="oval:org.mitre.oval:tst:3334"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:14526" version="5" class="vulnerability" deprecated="true">
      <metadata>
        <title>DEPRECATED: Unspecified vulnerability in IBM Tivoli Monitoring Agent (ITMA), as used in IBM DB2 9.5 before FP9 on UNIX, allows local users to gain privileges via unknown vectors.</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>IBM DB2 UDB</product>
        </affected>
        <reference ref_id="CVE-2012-1796" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1796" source="CVE"/>
        <description>Unspecified vulnerability in IBM Tivoli Monitoring Agent (ITMA), as used in IBM DB2 9.5 before FP9 on UNIX, allows local users to gain privileges via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2012-03-26T11:21:44.000-05:00">
              <contributor organization="DTCC">Scott Quint</contributor>
            </submitted>
            <status_change date="2012-03-27T14:24:34.554-04:00">DRAFT</status_change>
            <status_change date="2012-04-16T04:04:35.799-04:00">INTERIM</status_change>
            <status_change date="2012-05-07T04:00:11.756-04:00">ACCEPTED</status_change>
            <modified comment="Title indicates UNIX but Win platform defined" date="2013-07-26T13:41:27.190-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-26T13:41:27.190-04:00">DEPRECATED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:18040 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Determine if the version of IBM DB2 UDB is equal to 9.5">
          <extend_definition comment="IBM DB2 UDB is installed" definition_ref="oval:org.mitre.oval:def:12505"/>
          <criterion comment="Determine if the version of IBM DB2 UDB is equal to 9.5" test_ref="oval:org.mitre.oval:tst:77406"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1451" version="8" class="vulnerability">
      <metadata>
        <title>IE5 Multiple Event Handler Memory Corruption (Win2K)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1245" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1245"/>
        <description>Buffer overflow in mshtml.dll in Microsoft Internet Explorer 6.0.2900.2180, and probably other versions, allows remote attackers to execute arbitrary code via an HTML tag with a large number of script action handlers such as onload and onmouseover, as demonstrated using onclick, aka the "Multiple Event Handler Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Modified ste:831: altered regex to match on a double zero in the minor field of the version, and also added an initial anchor.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:27:00.230-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:28:36.308-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:43.805-05:00">ACCEPTED</status_change>
            <modified comment="Fixed regex in ste:2889.  Implemented by Matthew Wojcik." date="2007-03-06T18:19:00.507-05:00">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2007-03-06T18:21:05.654-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:16:49.318-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:46:44.537-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:01:02.159-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:59.737-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:17.520-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="Internet Explorer 5.01 (any patch level) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:927"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3839.2200" negate="false" test_ref="oval:org.mitre.oval:tst:926"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:14489" version="5" class="vulnerability">
      <metadata>
        <title>Stack-based buffer overflow in IBM Lotus Notes 8.5 and 8.5fp1, and possibly other versions, allows remote attackers to execute arbitrary code via unknown attack vectors, as demonstrated by the vd_ln module in VulnDisco 9.0.  NOTE: as of 20100222, this disclosure has no actionable information. However, because the VulnDisco author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Lotus Notes</product>
        </affected>
        <reference ref_id="CVE-2010-1608" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1608" source="CVE"/>
        <description>Stack-based buffer overflow in IBM Lotus Notes 8.5 and 8.5fp1, and possibly other versions, allows remote attackers to execute arbitrary code via unknown attack vectors, as demonstrated by the vd_ln module in VulnDisco 9.0.  NOTE: as of 20100222, this disclosure has no actionable information. However, because the VulnDisco author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-12-16T09:51:34.000-05:00">
              <contributor organization="DTCC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2011-12-19T15:44:15.335-05:00">DRAFT</status_change>
            <status_change date="2012-01-09T04:00:19.379-05:00">INTERIM</status_change>
            <status_change date="2012-01-30T04:00:33.111-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:14489 - registry_tests replaced with file_tests because registry path was compared with version" date="2015-05-29T11:02:00.629-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-05-29T11:05:01.542-04:00">INTERIM</status_change>
            <status_change date="2015-06-15T04:00:09.205-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Determine if the version of Lotus Notes is equal to 8.5">
          <extend_definition comment="IBM Lotus Notes is installed" definition_ref="oval:org.mitre.oval:def:11999"/>
          <criterion comment="Determine if the version of Lotus Notes is equal to 8.5" test_ref="oval:org.mitre.oval:tst:138693"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1446" version="8" class="vulnerability">
      <metadata>
        <title>IE5 COM Object Instantiation Memory Corruption (Win2K)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1186" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1186"/>
        <description>Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via by instantiating the (1) Mdt2gddr.dll, (2) Mdt2dd.dll, and (3) Mdt2gddo.dll COM objects as ActiveX controls, which leads to memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Modified ste:831: altered regex to match on a double zero in the minor field of the version, and also added an initial anchor.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:27:00.230-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:28:36.483-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:43.608-05:00">ACCEPTED</status_change>
            <modified comment="Fixed regex in ste:2889.  Implemented by Matthew Wojcik." date="2007-03-06T18:19:00.507-05:00">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2007-03-06T18:21:15.178-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:16:49.034-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:46:31.676-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:01:01.408-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:58.164-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:17.202-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="Internet Explorer 5.01 (any patch level) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:927"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3839.2200" negate="false" test_ref="oval:org.mitre.oval:tst:926"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1443" version="3" class="vulnerability">
      <metadata>
        <title>Firefox/Mozilla Suite about: Scheme Privilege Escalation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2706" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2706"/>
        <description>Firefox before 1.0.7 and Mozilla before Suite 1.7.12 allows remote attackers to execute Javascript with chrome privileges via an about: page such as about:mozilla.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-11T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-12T10:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:2367" date="2007-02-26T08:32:00.241-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-26T08:32:39.463-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:2370" date="2007-03-06T07:46:00.064-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:48.755-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:1444" date="2007-04-23T12:05:00.911-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:19:59.086-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:1445" date="2007-04-23T12:05:00.720-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:10:53.630-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Suite version 1.7.10 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.10 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2535"/>
          <criterion comment="Mozilla Suite version 1.7.10 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2534"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.6 or earlier is installed">
          <criterion comment="Firefox version 1.0.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2533"/>
          <criterion comment="Mozilla Firefox version 1.0.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2532"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1441" version="3" class="vulnerability">
      <metadata>
        <title>HTML Objects Memory Corruption Vulnerabilities</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0946" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0946"/>
        <description>Unspecified vulnerability in Microsoft Internet Explorer 7 on Windows XP SP2, Windows Server 2003 SP1 or SP2, or Windows Vista allows remote attackers to execute arbitrary code via crafted HTML objects, which results in memory corruption, aka the first of two "HTML Objects Memory Corruption Vulnerabilities" and a different issue than CVE-2007-0947.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-05-08T19:30:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-05-09T12:53:06-04:00">DRAFT</status_change>
            <status_change date="2007-05-31T15:26:33.138-04:00">INTERIM</status_change>
            <modified comment="Corrected version of ste:3224. Implemented by Jon Baker of the MITRE Corporation." date="2007-06-04T08:42:00.584-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <modified comment="Corrected criteria on 64 bit check" date="2007-06-07T08:42:00.584-04:00">
              <contributor organization="Secure Elements, Inc.">Jeff Ito</contributor>
            </modified>
            <status_change date="2007-06-22T08:57:40.311-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:3877 - modified comments" date="2014-02-28T15:13:00.247-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-28T15:16:17.011-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:10.706-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="IE 5.01,SP4 on Win2k,SP4" operator="AND">
          <extend_definition comment="Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Internet Explorer 5.01, SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3850.1900" test_ref="oval:org.mitre.oval:tst:3859"/>
        </criteria>
        <criteria comment="IE 6 on Windows 2000" operator="AND">
          <extend_definition comment="Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1593" test_ref="oval:org.mitre.oval:tst:3454"/>
        </criteria>
        <criteria comment="IE 6 on Windows XP SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1593" test_ref="oval:org.mitre.oval:tst:3454"/>
        </criteria>
        <criteria comment="XP,SP1 (64-bit) and Server 2003, SP1 (IE6)" operator="AND">
          <criteria operator="OR" comment="Windows XP (64-bit,SP1) or Server 2003 (SP1) is installed">
            <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          </criteria>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2885" test_ref="oval:org.mitre.oval:tst:3810"/>
        </criteria>
        <criteria comment="XP,SP2 (64-bit) and Server 2003, SP2 (IE6)" operator="AND">
          <criteria operator="OR" comment="Windows XP (64-bit,SP2) or Server 2003 (SP1) is installed">
            <criteria operator="AND" comment="Windows XP (64-bit,SP2) is installed">
              <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
              <criterion comment="64-Bit version of Windows is installed" test_ref="oval:org.mitre.oval:tst:2744"/>
            </criteria>
            <extend_definition comment="Windows Server 2003, SP2 is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          </criteria>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.4026" test_ref="oval:org.mitre.oval:tst:3176"/>
        </criteria>
        <criteria comment="IE 7 on Windows XP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="the version of Ieapfltr.dll is less than 7.0.6000.16432" test_ref="oval:org.mitre.oval:tst:3877"/>
        </criteria>
        <criteria comment="Windows Server 2003 Service Pack 1 version" operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 (x86) SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of Ieapfltr.dll is less than 7.0.6000.16432" test_ref="oval:org.mitre.oval:tst:3877"/>
        </criteria>
        <criteria comment="Windows Server 2003 Service Pack 2 version" operator="AND">
          <extend_definition comment="Microsoft Windows Server 2003 (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <criterion comment="the version of Ieapfltr.dll is less than 7.0.6000.16432" test_ref="oval:org.mitre.oval:tst:3877"/>
        </criteria>
        <criteria comment="IE 7 on Windows Vista" operator="AND">
          <extend_definition comment="Windows Vista is installed" definition_ref="oval:org.mitre.oval:def:228"/>
          <criterion comment="the version of mshtml.dll is less than 7.0.6000.20547" test_ref="oval:org.mitre.oval:tst:3334"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:144" version="4" class="vulnerability">
      <metadata>
        <title>Windows 2000 SNMPv1 Trap Handling DoS and Privilege Escalation (Test 1)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Simple Network Management Protocol (SNMP)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0012" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0012"/>
        <description>Vulnerabilities in a large number of SNMP implementations allow remote attackers to cause a denial of service or gain privileges via SNMPv1 trap handling, as demonstrated by the PROTOS c06-SNMPv1 test suite.  NOTE: It is highly likely that this candidate will be SPLIT into multiple candidates, one or more for each vendor.  This and other SNMP-related candidates will be updated when more accurate information is available.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <modified comment="Fixed regex in ste:2889.  Implemented by Matthew Wojcik." date="2007-03-06T18:19:00.507-05:00">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2007-03-06T18:21:07.344-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:16:48.570-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:30.710-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:01:00.630-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows 2000 (sp3 or earlier) is installed">
            <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
            <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3084"/>
          </criteria>
          <criterion comment="the version of snmp.exe is less than 5.0.2195.4919" negate="false" test_ref="oval:org.mitre.oval:tst:2883"/>
          <criterion comment="Patch Q314147 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2959"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the SNMP service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2958"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:14386" version="3" class="vulnerability">
      <metadata>
        <title>XSS in themeweb.aspx Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft SharePoint Server 2010</product>
          <product>Microsoft SharePoint Foundation 2010</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2012-0144" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0144"/>
        <description>Cross-site scripting (XSS) vulnerability in themeweb.aspx in Microsoft Office SharePoint Server 2010 Gold and SP1 and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via JavaScript sequences in a URL, aka "XSS in themeweb.aspx Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2012-02-14T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2012-02-21T12:28:23.117-05:00">DRAFT</status_change>
            <status_change date="2012-03-12T04:00:16.211-04:00">INTERIM</status_change>
            <status_change date="2012-04-02T04:00:09.824-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Vulnerable Microsoft Office SharePoint Server 2010">
          <extend_definition comment="Microsoft Office SharePoint Server 2010 is installed." definition_ref="oval:org.mitre.oval:def:12880"/>
          <criterion comment="Microsoft.SharePoint.Taxonomy.dll version is less than 14.0.6113.5000" test_ref="oval:org.mitre.oval:tst:78074"/>
        </criteria>
        <criteria comment="Vulnerable Microsoft SharePoint Foundation 2010">
          <extend_definition comment="Microsoft SharePoint Foundation 2010 is installed" definition_ref="oval:org.mitre.oval:def:12224"/>
          <criterion comment="OWSSVR.DLL version is less than 14.0.6114.5001" test_ref="oval:org.mitre.oval:tst:77961"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:14375" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft Malware Protection Engine Vulnerability-II</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Antigen for Exchange</product>
          <product>Microsoft Antigen for SMTP Gateway</product>
          <product>Microsoft Forefront Security for Exchange Server</product>
          <product>Microsoft Forefront Security for SharePoint</product>
          <product>Microsoft Windows Defender</product>
          <product>Windows Live OneCare</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1438" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1438"/>
        <description>Unspecified vulnerability in Microsoft Malware Protection Engine (mpengine.dll) 1.1.3520.0 and 0.1.13.192, as used in multiple Microsoft products, allows context-dependent attackers to cause a denial of service (disk space exhaustion) via a file with "crafted data structures" that trigger the creation of large temporary files, a different vulnerability than CVE-2008-1437.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-12-09T18:23:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-12-09T17:34:55.550-05:00">DRAFT</status_change>
            <status_change date="2011-12-26T04:02:10.341-05:00">INTERIM</status_change>
            <status_change date="2012-01-16T04:02:25.976-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Live OneCare">
          <extend_definition comment="Microsoft Windows Live OneCare is installed" definition_ref="oval:org.mitre.oval:def:14185"/>
          <criterion comment="Check if Live OneCare EngineVersion is less than 1.1.3520.0" test_ref="oval:org.mitre.oval:tst:77776"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Windows Defender">
          <extend_definition comment="Microsoft Windows Defender is installed" definition_ref="oval:org.mitre.oval:def:14263"/>
          <criterion comment="Check if Windows Defender EngineVersion is less than 1.1.3520.0" test_ref="oval:org.mitre.oval:tst:77823"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Forefront Security for SharePoint">
          <extend_definition comment="Microsoft Forefront Security for SharePoint is installed" definition_ref="oval:org.mitre.oval:def:14529"/>
          <criterion comment="Check if Forefront Security for SharePoint EngineVersion is less than 0.1.13.192" test_ref="oval:org.mitre.oval:tst:77719"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Forefront Security for Exchange Server">
          <extend_definition comment="Microsoft Forefront Security for Exchange Server is installed" definition_ref="oval:org.mitre.oval:def:14468"/>
          <criterion comment="Check if Forefront Security for Exchange Server EngineVersion is less than 0.1.13.192" test_ref="oval:org.mitre.oval:tst:77774"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Antigen for Exchange">
          <extend_definition comment="Microsoft Antigen for Exchange is installed" definition_ref="oval:org.mitre.oval:def:14520"/>
          <criterion comment="Check if Antigen for Exchange EngineVersion is less than 0.1.13.192" test_ref="oval:org.mitre.oval:tst:77829"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Antigen for SMTP Gateway">
          <extend_definition comment="Microsoft Antigen for SMTP Gateway is installed" definition_ref="oval:org.mitre.oval:def:14251"/>
          <criterion comment="Check if Antigen for SMTP Gateway EngineVersion is less than 0.1.13.192" test_ref="oval:org.mitre.oval:tst:77570"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:14348" version="5" class="vulnerability">
      <metadata>
        <title>Argument injection vulnerability in IBM Lotus Notes 8.0.x before 8.0.2 FP6 and 8.5.x before 8.5.1 FP5 allows remote attackers to execute arbitrary code via a cai:// URL containing a --launcher.library option that specifies a UNC share pathname for a DLL file, aka SPR PRAD82YJW2.</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Lotus Notes</product>
        </affected>
        <reference ref_id="CVE-2011-0912" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0912" source="CVE"/>
        <description>Argument injection vulnerability in IBM Lotus Notes 8.0.x before 8.0.2 FP6 and 8.5.x before 8.5.1 FP5 allows remote attackers to execute arbitrary code via a cai:// URL containing a --launcher.library option that specifies a UNC share pathname for a DLL file, aka SPR PRAD82YJW2.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-12-16T09:51:41.000-05:00">
              <contributor organization="DTCC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2011-12-19T15:44:08.369-05:00">DRAFT</status_change>
            <status_change date="2012-01-09T04:00:17.643-05:00">INTERIM</status_change>
            <status_change date="2012-01-30T04:00:31.598-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:14348 - registry_tests replaced with file_tests because registry path was compared with version" date="2015-05-29T11:02:00.629-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-05-29T11:05:02.656-04:00">INTERIM</status_change>
            <status_change date="2015-06-15T04:00:08.958-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Determine if the version of Lotus Notes is less than or equal to 8.5.1.4 and is greater than or equal to 8.0.1">
          <extend_definition comment="IBM Lotus Notes is installed" definition_ref="oval:org.mitre.oval:def:11999"/>
          <criterion comment="Determine if the version of Lotus Notes is less than or equal to 8.5.1.4" test_ref="oval:org.mitre.oval:tst:138083"/>
          <criterion comment="Determine if the version of Lotus Notes is greater than or equal to 8.0.1" test_ref="oval:org.mitre.oval:tst:138392"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1431" version="6" class="vulnerability">
      <metadata>
        <title>Win2K Graphics Rendering Engine Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-4560" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4560"/>
        <description>The Windows Graphical Device Interface library (GDI32.DLL) in Microsoft Windows allows remote attackers to execute arbitrary code via a Windows Metafile (WMF) format image with a crafted SETABORTPROC GDI Escape function call, related to the Windows Picture and Fax Viewer (SHIMGVW.DLL), a different vulnerability than CVE-2005-2123 and CVE-2005-2124, and as originally discovered in the wild on unionseek.com.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-07T07:15:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-12T09:25:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-01T09:08:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed regex in ste:2889.  Implemented by Matthew Wojcik." date="2007-03-06T18:19:00.507-05:00">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2007-03-06T18:21:15.598-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:16:48.356-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1431 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:05:41.063-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:00:59.302-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="the version of Gdi32.dll is less than 5.0.2195.7073" test_ref="oval:org.mitre.oval:tst:943"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:14309" version="7" class="vulnerability">
      <metadata>
        <title>Stack-based buffer overflow in rtfsr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted link in a .rtf attachment, aka SPR PRAD8823JQ.</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Lotus Notes</product>
        </affected>
        <reference ref_id="CVE-2011-1214" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1214" source="CVE"/>
        <description>Stack-based buffer overflow in rtfsr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted link in a .rtf attachment, aka SPR PRAD8823JQ.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-12-16T09:51:46.000-05:00">
              <contributor organization="DTCC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2011-12-19T15:44:13.930-05:00">DRAFT</status_change>
            <status_change date="2012-01-09T04:00:15.269-05:00">INTERIM</status_change>
            <status_change date="2012-01-30T04:00:29.654-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.altx-soft.oval:ste:18430 - contains tests with modified comments and all dependences" date="2014-02-13T12:19:00.287-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:22:40.167-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:00:43.061-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:14309 - registry_tests replaced with file_tests because registry path was compared with version" date="2015-05-29T11:02:00.629-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-05-29T11:05:02.149-04:00">INTERIM</status_change>
            <status_change date="2015-06-15T04:00:08.643-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Determine if the version of Lotus Notes is less than or equal to 8.5.2.2 and is greater than or equal to 8.0.0">
          <extend_definition comment="IBM Lotus Notes is installed" definition_ref="oval:org.mitre.oval:def:11999"/>
          <criterion comment="Determine if the version of Lotus Notes is less than or equal to 8.5.2.2" test_ref="oval:org.mitre.oval:tst:138913"/>
          <criterion comment="Determine if the version of Lotus Notes is greater than or equal to 8.0.0" test_ref="oval:org.mitre.oval:tst:138507"/>
        </criteria>
        <criteria operator="AND" comment="Determine if the version of Lotus Notes is less than or equal to 7.0.4 and is greater than or equal to 7.0.0">
          <extend_definition comment="IBM Lotus Notes is installed" definition_ref="oval:org.mitre.oval:def:11999"/>
          <criterion comment="Determine if the version of Lotus Notes is less than or equal to 7.0.4" test_ref="oval:org.mitre.oval:tst:138653"/>
          <criterion comment="Determine if the version of Lotus Notes is greater than or equal to 7.0.0" test_ref="oval:org.mitre.oval:tst:138900"/>
        </criteria>
        <criteria operator="AND" comment="Determine if the version of Lotus Notes is less than or equal to 6.5.6 and is greater than or equal to 6.0.1">
          <extend_definition comment="IBM Lotus Notes is installed" definition_ref="oval:org.mitre.oval:def:11999"/>
          <criterion comment="Determine if the version of Lotus Notes is less than or equal to 6.5.6" test_ref="oval:org.mitre.oval:tst:138776"/>
          <criterion comment="Determine if the version of Lotus Notes is greater than or equal to 6.0.1" test_ref="oval:org.mitre.oval:tst:138813"/>
        </criteria>
        <criteria operator="AND" comment="Determine if the version of Lotus Notes is less than or equal to 5.2 and is greater than or equal to 5:0a">
          <extend_definition comment="IBM Lotus Notes is installed" definition_ref="oval:org.mitre.oval:def:11999"/>
          <criterion comment="Determine if the version of Lotus Notes is less than or equal to 5.2" test_ref="oval:org.mitre.oval:tst:138910"/>
          <criterion comment="Determine if the version of Lotus Notes is greater than or equal to 5:0a" test_ref="oval:org.mitre.oval:tst:138741"/>
        </criteria>
        <criteria operator="AND" comment="Determine if the version of Lotus Notes is less than or equal to 4.6 and is greater than or equal to 4.2.1">
          <extend_definition comment="IBM Lotus Notes is installed" definition_ref="oval:org.mitre.oval:def:11999"/>
          <criterion comment="Determine if the version of Lotus Notes is less than or equal to 4.6" test_ref="oval:org.mitre.oval:tst:138685"/>
          <criterion comment="Determine if the version of Lotus Notes is greater than or equal to 4.2.1" test_ref="oval:org.mitre.oval:tst:138657"/>
        </criteria>
        <criteria operator="AND" comment="Determine if the version of Lotus Notes is less than or equal to 3.0.0.2 and is greater than or equal to 3.0.0.1">
          <extend_definition comment="IBM Lotus Notes is installed" definition_ref="oval:org.mitre.oval:def:11999"/>
          <criterion comment="Determine if the version of Lotus Notes is less than or equal to 3.0.0.2" test_ref="oval:org.mitre.oval:tst:138223"/>
          <criterion comment="Determine if the version of Lotus Notes is greater than or equal to 3.0.0.1" test_ref="oval:org.mitre.oval:tst:138612"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:143" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft IE Encoded Characters Information Disclosure</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1186" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1186"/>
        <description>Internet Explorer 5.01 through 6.0 does not properly perform security checks on certain encoded characters within a URL, which allows a remote attacker to steal potentially sensitive information from a user by redirecting the user to another site that has that information, aka "Encoded Characters Information Disclosure."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-27T05:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Changed IE registry test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:39.232-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:16.674-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the version of mshtml.dll is less than 6.0.2722.900" negate="false" test_ref="oval:org.mitre.oval:tst:2884"/>
        <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
        <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
        <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:14289" version="4" class="vulnerability" deprecated="true">
      <metadata>
        <title>DEPRECATED: kuddb2 in Tivoli Monitoring for DB2, as distributed in IBM DB2 9.7 FP1 on Linux, allows remote attackers to cause a denial of service (daemon crash) via a certain byte sequence.</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>IBM DB2 UDB</product>
        </affected>
        <reference ref_id="CVE-2010-0472" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0472" source="CVE"/>
        <description>kuddb2 in Tivoli Monitoring for DB2, as distributed in IBM DB2 9.7 FP1 on Linux, allows remote attackers to cause a denial of service (daemon crash) via a certain byte sequence.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-12-16T09:51:32.000-05:00">
              <contributor organization="DTCC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2011-12-19T15:44:13.207-05:00">DRAFT</status_change>
            <status_change date="2012-01-09T04:00:13.273-05:00">INTERIM</status_change>
            <status_change date="2012-01-30T04:00:28.126-05:00">ACCEPTED</status_change>
            <modified comment="Linux vulnerability being checked on Windows platform." date="2013-07-18T09:09:13.004-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-18T09:09:13.004-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Determine if the version of IBM DB2 UDB is equal to 9.7.0.1">
          <extend_definition comment="IBM DB2 UDB is installed" definition_ref="oval:org.mitre.oval:def:12505"/>
          <criterion comment="Determine if the version of IBM DB2 UDB is equal to 9.7.0.1" test_ref="oval:org.mitre.oval:tst:77535"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12505" version="3" class="inventory">
      <metadata>
        <title>IBM DB2 UDB is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>IBM DB2</product>
        </affected>
        <reference ref_id="cpe:/a:ibm:db2" source="CPE"/>
        <description>IBM DB2 UDB is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2011-02-25T10:21:36">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-02-28T09:40:31.670-05:00">DRAFT</status_change>
            <status_change date="2011-03-21T04:00:12.165-04:00">INTERIM</status_change>
            <status_change date="2011-04-11T04:00:09.587-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if IBM DB2 UDB is installed" test_ref="oval:org.mitre.oval:tst:42372"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:14238" version="7" class="vulnerability">
      <metadata>
        <title>Buffer overflow in kvarcve.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted .zip attachment, aka SPR PRAD8E3NSP. NOTE: some of these details are obtained from third party information.</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Lotus Notes</product>
        </affected>
        <reference ref_id="CVE-2011-1218" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1218" source="CVE"/>
        <description>Buffer overflow in kvarcve.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted .zip attachment, aka SPR PRAD8E3NSP. NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-12-16T09:51:54.000-05:00">
              <contributor organization="DTCC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2011-12-19T15:44:07.172-05:00">DRAFT</status_change>
            <status_change date="2012-01-09T04:00:11.745-05:00">INTERIM</status_change>
            <status_change date="2012-01-30T04:00:26.951-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.altx-soft.oval:ste:18430 - contains tests with modified comments and all dependences" date="2014-02-13T12:19:00.287-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:22:41.660-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:00:42.240-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:14238 - registry_tests replaced with file_tests because registry path was compared with version" date="2015-05-29T11:02:00.629-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-05-29T11:05:01.916-04:00">INTERIM</status_change>
            <status_change date="2015-06-15T04:00:08.338-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Determine if the version of Lotus Notes is less than or equal to 8.5.2.2 and is greater than or equal to 8.0.0">
          <extend_definition comment="IBM Lotus Notes is installed" definition_ref="oval:org.mitre.oval:def:11999"/>
          <criterion comment="Determine if the version of Lotus Notes is less than or equal to 8.5.2.2" test_ref="oval:org.mitre.oval:tst:138913"/>
          <criterion comment="Determine if the version of Lotus Notes is greater than or equal to 8.0.0" test_ref="oval:org.mitre.oval:tst:138507"/>
        </criteria>
        <criteria operator="AND" comment="Determine if the version of Lotus Notes is less than or equal to 7.0.4 and is greater than or equal to 7.0.0">
          <extend_definition comment="IBM Lotus Notes is installed" definition_ref="oval:org.mitre.oval:def:11999"/>
          <criterion comment="Determine if the version of Lotus Notes is less than or equal to 7.0.4" test_ref="oval:org.mitre.oval:tst:138653"/>
          <criterion comment="Determine if the version of Lotus Notes is greater than or equal to 7.0.0" test_ref="oval:org.mitre.oval:tst:138900"/>
        </criteria>
        <criteria operator="AND" comment="Determine if the version of Lotus Notes is less than or equal to 6.5.6 and is greater than or equal to 6.0.1">
          <extend_definition comment="IBM Lotus Notes is installed" definition_ref="oval:org.mitre.oval:def:11999"/>
          <criterion comment="Determine if the version of Lotus Notes is less than or equal to 6.5.6" test_ref="oval:org.mitre.oval:tst:138776"/>
          <criterion comment="Determine if the version of Lotus Notes is greater than or equal to 6.0.1" test_ref="oval:org.mitre.oval:tst:138813"/>
        </criteria>
        <criteria operator="AND" comment="Determine if the version of Lotus Notes is less than or equal to 5.2 and is greater than or equal to 5:0a">
          <extend_definition comment="IBM Lotus Notes is installed" definition_ref="oval:org.mitre.oval:def:11999"/>
          <criterion comment="Determine if the version of Lotus Notes is less than or equal to 5.2" test_ref="oval:org.mitre.oval:tst:138910"/>
          <criterion comment="Determine if the version of Lotus Notes is greater than or equal to 5:0a" test_ref="oval:org.mitre.oval:tst:138741"/>
        </criteria>
        <criteria operator="AND" comment="Determine if the version of Lotus Notes is less than or equal to 4.6 and is greater than or equal to 4.2.1">
          <extend_definition comment="IBM Lotus Notes is installed" definition_ref="oval:org.mitre.oval:def:11999"/>
          <criterion comment="Determine if the version of Lotus Notes is less than or equal to 4.6" test_ref="oval:org.mitre.oval:tst:138685"/>
          <criterion comment="Determine if the version of Lotus Notes is greater than or equal to 4.2.1" test_ref="oval:org.mitre.oval:tst:138657"/>
        </criteria>
        <criteria operator="AND" comment="Determine if the version of Lotus Notes is less than or equal to 3.0.0.2 and is greater than or equal to 3.0.0.1">
          <extend_definition comment="IBM Lotus Notes is installed" definition_ref="oval:org.mitre.oval:def:11999"/>
          <criterion comment="Determine if the version of Lotus Notes is less than or equal to 3.0.0.2" test_ref="oval:org.mitre.oval:tst:138223"/>
          <criterion comment="Determine if the version of Lotus Notes is greater than or equal to 3.0.0.1" test_ref="oval:org.mitre.oval:tst:138612"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:14203" version="7" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in xlssr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a malformed BIFF record in a .xls Excel spreadsheet attachment, aka SPR PRAD8E3HKR.</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Lotus Notes</product>
        </affected>
        <reference ref_id="CVE-2011-1512" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1512" source="CVE"/>
        <description>Heap-based buffer overflow in xlssr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a malformed BIFF record in a .xls Excel spreadsheet attachment, aka SPR PRAD8E3HKR.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-12-16T09:51:57.000-05:00">
              <contributor organization="DTCC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2011-12-19T15:44:12.711-05:00">DRAFT</status_change>
            <status_change date="2012-01-09T04:00:10.856-05:00">INTERIM</status_change>
            <status_change date="2012-01-30T04:00:26.236-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.altx-soft.oval:ste:18430 - contains tests with modified comments and all dependences" date="2014-02-13T12:19:00.287-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:22:41.573-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:00:42.019-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:14203 - registry_tests replaced with file_tests because registry path was compared with version" date="2015-05-29T11:02:00.629-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-05-29T11:05:02.978-04:00">INTERIM</status_change>
            <status_change date="2015-06-15T04:00:08.022-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Determine if the version of Lotus Notes is less than or equal to 8.5.2.2 and is greater than or equal to 8.0.0">
          <extend_definition comment="IBM Lotus Notes is installed" definition_ref="oval:org.mitre.oval:def:11999"/>
          <criterion comment="Determine if the version of Lotus Notes is less than or equal to 8.5.2.2" test_ref="oval:org.mitre.oval:tst:138913"/>
          <criterion comment="Determine if the version of Lotus Notes is greater than or equal to 8.0.0" test_ref="oval:org.mitre.oval:tst:138507"/>
        </criteria>
        <criteria operator="AND" comment="Determine if the version of Lotus Notes is less than or equal to 7.0.4 and is greater than or equal to 7.0.0">
          <extend_definition comment="IBM Lotus Notes is installed" definition_ref="oval:org.mitre.oval:def:11999"/>
          <criterion comment="Determine if the version of Lotus Notes is less than or equal to 7.0.4" test_ref="oval:org.mitre.oval:tst:138653"/>
          <criterion comment="Determine if the version of Lotus Notes is greater than or equal to 7.0.0" test_ref="oval:org.mitre.oval:tst:138900"/>
        </criteria>
        <criteria operator="AND" comment="Determine if the version of Lotus Notes is less than or equal to 6.5.6 and is greater than or equal to 6.0.1">
          <extend_definition comment="IBM Lotus Notes is installed" definition_ref="oval:org.mitre.oval:def:11999"/>
          <criterion comment="Determine if the version of Lotus Notes is less than or equal to 6.5.6" test_ref="oval:org.mitre.oval:tst:138776"/>
          <criterion comment="Determine if the version of Lotus Notes is greater than or equal to 6.0.1" test_ref="oval:org.mitre.oval:tst:138813"/>
        </criteria>
        <criteria operator="AND" comment="Determine if the version of Lotus Notes is less than or equal to 5.2 and is greater than or equal to 5:0a">
          <extend_definition comment="IBM Lotus Notes is installed" definition_ref="oval:org.mitre.oval:def:11999"/>
          <criterion comment="Determine if the version of Lotus Notes is less than or equal to 5.2" test_ref="oval:org.mitre.oval:tst:138910"/>
          <criterion comment="Determine if the version of Lotus Notes is greater than or equal to 5:0a" test_ref="oval:org.mitre.oval:tst:138741"/>
        </criteria>
        <criteria operator="AND" comment="Determine if the version of Lotus Notes is less than or equal to 4.6 and is greater than or equal to 4.2.1">
          <extend_definition comment="IBM Lotus Notes is installed" definition_ref="oval:org.mitre.oval:def:11999"/>
          <criterion comment="Determine if the version of Lotus Notes is less than or equal to 4.6" test_ref="oval:org.mitre.oval:tst:138685"/>
          <criterion comment="Determine if the version of Lotus Notes is greater than or equal to 4.2.1" test_ref="oval:org.mitre.oval:tst:138657"/>
        </criteria>
        <criteria operator="AND" comment="Determine if the version of Lotus Notes is less than or equal to 3.0.0.2 and is greater than or equal to 3.0.0.1">
          <extend_definition comment="IBM Lotus Notes is installed" definition_ref="oval:org.mitre.oval:def:11999"/>
          <criterion comment="Determine if the version of Lotus Notes is less than or equal to 3.0.0.2" test_ref="oval:org.mitre.oval:tst:138223"/>
          <criterion comment="Determine if the version of Lotus Notes is greater than or equal to 3.0.0.1" test_ref="oval:org.mitre.oval:tst:138612"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1420" version="6" class="vulnerability">
      <metadata>
        <title>Buffer Overflow in CDOSYS Message Processing (Win2K,SP4)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1987" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1987"/>
        <description>Buffer overflow in Collaboration Data Objects (CDO), as used in Microsoft Windows and Microsoft Exchange Server, allows remote attackers to execute arbitrary code when CDOSYS or CDOEX processes an e-mail message with a large header name, as demonstrated using the "Content-Type" string.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-31T12:00:00.000-04:00" comment="removed an incorrect leading ^ from the value entity of ste:2402">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-31T00:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:18.350-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1420 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:06:37.292-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:00:57.283-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Windows 2000 is installed" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="Win2K/XP/2003 service pack 4 is installed" test_ref="oval:org.mitre.oval:tst:2569"/>
        <criterion comment="cdosys.dll is less than 6.1.3940.42" test_ref="oval:org.mitre.oval:tst:953"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1414" version="8" class="vulnerability">
      <metadata>
        <title>HTML Decoding Memory Corruption Vulnerability (Win2K)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2382" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2382"/>
        <description>Heap-based buffer overflow in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remote attackers to execute arbitrary code via crafted UTF-8 encoded HTML that results in size discrepancies during conversion to Unicode, aka "HTML Decoding Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:18.013-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:05.786-04:00">ACCEPTED</status_change>
            <modified comment="Fixed ste:2614: set datatype to version.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:54:00.319-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:59:40.114-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:42.558-05:00">ACCEPTED</status_change>
            <modified comment="Fixed regex in ste:2889.  Implemented by Matthew Wojcik." date="2007-03-06T18:19:00.507-05:00">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2007-03-06T18:21:11.835-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:16:48.126-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:28.349-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:00:56.599-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:38.742-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:16.320-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3841.1900" negate="false" test_ref="oval:org.mitre.oval:tst:957"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:141" version="8" class="vulnerability">
      <metadata>
        <title>Microsoft Internet Explorer MIME Hack</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0154" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0154"/>
        <description>HTML e-mail feature in Internet Explorer 5.5 and earlier allows attackers to execute attachments by setting an unusual MIME type for the attachment, which Internet Explorer does not process correctly.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-07-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if file downloads are enabled by the current user when local machine settings are not in use.  Changed the status from ACCEPTED to INTERIM">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2875 set datatype to version on version element. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-12T20:46:00.631-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-12T20:47:59.211-05:00">INTERIM</status_change>
            <modified comment="Corrected ste:2873. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-12T20:52:00.978-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <modified comment="Corrected ste:2874. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-12T21:00:00.301-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <modified comment="Corrected ste:2871. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-12T21:03:00.158-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <modified comment="Corrected ste:2872. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-12T21:06:00.183-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <modified comment="Corrected ste:2870. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:36:00.896-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-02-20T13:39:42.096-05:00">ACCEPTED</status_change>
            <modified comment="Updated comment to include Vista and Server 2008" date="2009-05-07T10:32:00.713-04:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2009-05-07T10:34:11.206-04:00">INTERIM</status_change>
            <status_change date="2009-05-25T04:00:51.221-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:30.248-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:00:55.670-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:38.999-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:16.015-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Software section">
          <criteria operator="OR" comment="Internet Explorer 5.01 Installed">
            <criterion comment="Internet Explorer 5.01 Installed" test_ref="oval:org.mitre.oval:tst:3070"/>
            <criterion comment="Internet Explorer 5.01 Installed" test_ref="oval:org.mitre.oval:tst:3069"/>
            <criterion comment="Internet Explorer 5.01 Installed" test_ref="oval:org.mitre.oval:tst:3068"/>
            <criterion comment="Internet Explorer 5.01 Installed" test_ref="oval:org.mitre.oval:tst:3067"/>
            <criterion comment="Internet Explorer 5.01 Installed" test_ref="oval:org.mitre.oval:tst:3066"/>
            <criterion comment="Internet Explorer 5.01 Installed" test_ref="oval:org.mitre.oval:tst:3065"/>
          </criteria>
          <criterion comment="File %windir%\system32\shdocvw.dll version is less than 5.0.3214.2000" test_ref="oval:org.mitre.oval:tst:2892"/>
          <criterion negate="true" comment="the patch q290108 is installed" test_ref="oval:org.mitre.oval:tst:2891"/>
          <criterion negate="true" comment="the patch q295106 is installed" test_ref="oval:org.mitre.oval:tst:2890"/>
          <criterion negate="true" comment="Win2K/XP/2003/Vista/2008 Service Pack 2 is installed" test_ref="oval:org.mitre.oval:tst:3019"/>
        </criteria>
        <criteria operator="AND" comment="Configuration section">
          <criteria operator="AND" comment="file downloads are enabled">
            <criteria operator="AND" comment="current user settings are being used and file downloads are enabled">
              <criterion negate="true" comment="use machine settings rather than individual user settings" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="file downloads are enabled for the local machine" test_ref="oval:org.mitre.oval:tst:2889"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and file downloads are enabled">
              <criterion comment="use machine settings rather than individual user settings" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="file downloads are enabled for the current user" test_ref="oval:org.mitre.oval:tst:2888"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:14052" version="4" class="vulnerability">
      <metadata>
        <title>Convert Buffer Overrun Vulnerability in SQL Server</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft SQL Server 2000</product>
          <product>Microsoft SQL Server 2000 Desktop Engine (WMSDE)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0086" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0086"/>
        <description>Buffer overflow in the convert function in Microsoft SQL Server 2000 SP4, 2000 Desktop Engine (MSDE 2000) SP4, and 2000 Desktop Engine (WMSDE) allows remote authenticated users to execute arbitrary code via a crafted SQL expression.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-11-15T14:16:37">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-11-15T14:48:17.655-05:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:9191 - Submitting 4 CVE definitions for MS08-040 bulletin that were missed in oval repo" date="2011-11-15T14:47:00.058-05:00">
              <contributor organization="SecPod Technologies">Pradeep R B</contributor>
            </modified>
            <status_change date="2011-12-05T04:00:22.151-05:00">INTERIM</status_change>
            <status_change date="2011-12-26T04:00:50.298-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="SQL Server 2000 SP4 - GDR">
          <criterion comment="SQL Server 2000 is installed" test_ref="oval:org.mitre.oval:tst:2977"/>
          <criterion comment="SQL Server 2000 GDR - the version of sqlservr.exe is greater than 2000.80.2000.0" test_ref="oval:org.mitre.oval:tst:9683"/>
          <criterion comment="Check if version of Sqlservr.exe is less than 2000.80.2050.0" test_ref="oval:org.mitre.oval:tst:77466"/>
        </criteria>
        <criteria operator="AND" comment="SQL Server 2000 SP4- QFE">
          <criterion comment="SQL Server 2000 is installed" test_ref="oval:org.mitre.oval:tst:2977"/>
          <criterion comment="SQL Server 2000 QFE - the version of sqlservr.exe is greater than 2000.80.2000.0" test_ref="oval:org.mitre.oval:tst:9191"/>
          <criterion comment="Check if version of Sqlservr.exe is less than 2000.80.2273.0" test_ref="oval:org.mitre.oval:tst:77541"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:13981" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft Malware Protection Engine Vulnerability-I</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Antigen for Exchange</product>
          <product>Microsoft Antigen for SMTP Gateway</product>
          <product>Microsoft Forefront Security for Exchange Server</product>
          <product>Microsoft Forefront Security for SharePoint</product>
          <product>Microsoft Windows Defender</product>
          <product>Windows Live OneCare</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1437" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1437"/>
        <description>Unspecified vulnerability in Microsoft Malware Protection Engine (mpengine.dll) 1.1.3520.0 and 0.1.13.192, as used in multiple Microsoft products, allows context-dependent attackers to cause a denial of service (engine hang and restart) via a crafted file, a different vulnerability than CVE-2008-1438.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-12-09T18:23:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-12-09T17:34:55.155-05:00">DRAFT</status_change>
            <status_change date="2011-12-26T04:00:37.472-05:00">INTERIM</status_change>
            <status_change date="2012-01-16T04:00:46.641-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Live OneCare">
          <extend_definition comment="Microsoft Windows Live OneCare is installed" definition_ref="oval:org.mitre.oval:def:14185"/>
          <criterion comment="Check if Live OneCare EngineVersion is less than 1.1.3520.0" test_ref="oval:org.mitre.oval:tst:77776"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Windows Defender">
          <extend_definition comment="Microsoft Windows Defender is installed" definition_ref="oval:org.mitre.oval:def:14263"/>
          <criterion comment="Check if Windows Defender EngineVersion is less than 1.1.3520.0" test_ref="oval:org.mitre.oval:tst:77823"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Forefront Security for SharePoint">
          <extend_definition comment="Microsoft Forefront Security for SharePoint is installed" definition_ref="oval:org.mitre.oval:def:14529"/>
          <criterion comment="Check if Forefront Security for SharePoint EngineVersion is less than 0.1.13.192" test_ref="oval:org.mitre.oval:tst:77719"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Forefront Security for Exchange Server">
          <extend_definition comment="Microsoft Forefront Security for Exchange Server is installed" definition_ref="oval:org.mitre.oval:def:14468"/>
          <criterion comment="Check if Forefront Security for Exchange Server EngineVersion is less than 0.1.13.192" test_ref="oval:org.mitre.oval:tst:77774"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Antigen for Exchange">
          <extend_definition comment="Microsoft Antigen for Exchange is installed" definition_ref="oval:org.mitre.oval:def:14520"/>
          <criterion comment="Check if Antigen for Exchange EngineVersion is less than 0.1.13.192" test_ref="oval:org.mitre.oval:tst:77829"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Antigen for SMTP Gateway">
          <extend_definition comment="Microsoft Antigen for SMTP Gateway is installed" definition_ref="oval:org.mitre.oval:def:14251"/>
          <criterion comment="Check if Antigen for SMTP Gateway EngineVersion is less than 0.1.13.192" test_ref="oval:org.mitre.oval:tst:77570"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:14529" version="3" class="inventory">
      <metadata>
        <title>Microsoft Forefront Security for SharePoint is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Forefront Security for SharePoint</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:forefront_security_for_sharepoint"/>
        <description>Microsoft Forefront Security for SharePoint is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-12-09T16:11:37">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-12-09T17:34:54.386-05:00">DRAFT</status_change>
            <status_change date="2011-12-26T04:02:48.347-05:00">INTERIM</status_change>
            <status_change date="2012-01-16T04:03:00.910-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Microsoft Forefront Security for SharePoint is installed" test_ref="oval:org.mitre.oval:tst:77468"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:14520" version="3" class="inventory">
      <metadata>
        <title>Microsoft Antigen for Exchange is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Antigen for Exchange</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:antigen_for_exchange"/>
        <description>Microsoft Antigen for Exchange is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-12-09T10:57:56">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-12-09T17:34:53.185-05:00">DRAFT</status_change>
            <status_change date="2011-12-26T04:02:46.082-05:00">INTERIM</status_change>
            <status_change date="2012-01-16T04:02:58.754-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Microsoft Antigen for Exchange is installed" test_ref="oval:org.mitre.oval:tst:77816"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:14468" version="3" class="inventory">
      <metadata>
        <title>Microsoft Forefront Security for Exchange Server is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Forefront Security for Exchange Server</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:forefront_security_for_exchange_server"/>
        <description>Microsoft Forefront Security for Exchange Server is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-12-09T18:41:38">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-12-09T17:34:54.644-05:00">DRAFT</status_change>
            <status_change date="2011-12-26T04:02:33.855-05:00">INTERIM</status_change>
            <status_change date="2012-01-16T04:02:48.886-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Microsoft Forefront Security for Exchange Server is installed" test_ref="oval:org.mitre.oval:tst:77631"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:14263" version="5" class="inventory">
      <metadata>
        <title>Microsoft Windows Defender is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft Windows Defender</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:windows_defender"/>
        <description>Microsoft Windows Defender is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-12-09T17:29:19">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-12-09T17:34:54.128-05:00">DRAFT</status_change>
            <status_change date="2011-12-26T04:01:39.741-05:00">INTERIM</status_change>
            <status_change date="2012-01-16T04:01:51.984-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:14263 - Submission on Microsoft Bulletins for the month April-2013." date="2013-04-15T21:05:00.274-04:00">
              <contributor organization="SecPod Technologies">Bhavya K</contributor>
            </modified>
            <status_change date="2013-04-15T21:11:36.704-04:00">INTERIM</status_change>
            <status_change date="2013-05-06T04:01:16.560-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Microsoft Windows Defender is installed" test_ref="oval:org.mitre.oval:tst:77748"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:14251" version="3" class="inventory">
      <metadata>
        <title>Microsoft Antigen for SMTP Gateway is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Antigen for SMTP Gateway</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:antigen_for_smtp_gateway"/>
        <description>Microsoft Antigen for SMTP Gateway is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-12-09T10:57:56">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-12-09T17:34:54.896-05:00">DRAFT</status_change>
            <status_change date="2011-12-26T04:01:35.292-05:00">INTERIM</status_change>
            <status_change date="2012-01-16T04:01:47.978-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Microsoft Antigen for SMTP Gateway is installed" test_ref="oval:org.mitre.oval:tst:77523"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:14185" version="3" class="inventory">
      <metadata>
        <title>Microsoft Windows Live OneCare is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Windows Live OneCare</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:windows_live_onecare"/>
        <description>Microsoft Windows Live OneCare is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-12-09T15:46:11">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-12-09T17:34:53.852-05:00">DRAFT</status_change>
            <status_change date="2011-12-26T04:01:16.172-05:00">INTERIM</status_change>
            <status_change date="2012-01-16T04:01:27.846-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Microsoft Windows Live OneCare is installed" test_ref="oval:org.mitre.oval:tst:77777"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1396" version="7" class="vulnerability">
      <metadata>
        <title>CSS Tag Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference ref_id="CVE-2007-1750" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1750" source="CVE"/>
        <description>Unspecified vulnerability in Microsoft Internet Explorer 6 allows remote attackers to execute arbitrary code via a crafted Cascading Style Sheets (CSS) tag that triggers memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-06-13T08:22:59.000-04:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-06-13T15:20:00.000-04:00">DRAFT</status_change>
            <modified comment="Changed Office 2003 test to Visio 2003." date="2007-06-15T14:14:00.128-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <modified comment="Added Vista as an affected platform." date="2007-06-16T11:51:00.325-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-07-03T14:05:54.644-04:00">INTERIM</status_change>
            <status_change date="2007-07-18T15:57:49.309-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1396 - Updates made to criteria user correct IDs and comments." date="2011-01-07T14:47:00.308-05:00">
              <contributor organization="G2, Inc.">Jeff Cockerill</contributor>
            </modified>
            <status_change date="2011-01-07T14:52:39.970-05:00">INTERIM</status_change>
            <status_change date="2011-01-24T04:00:30.859-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1396 - Correcting incorrect references to 64-bit Itanium XP." date="2012-08-23T17:47:00.168-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-08-23T17:52:13.733-04:00">INTERIM</status_change>
            <status_change date="2012-09-10T04:00:06.413-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:29:00.241-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:15.712-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 on Win 2k, SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the version of Mshtml.dll is less than 6.0.2800.1595" test_ref="oval:org.mitre.oval:tst:3202"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win XP SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of Mshtml.dll is less than 6.0.2900.3132" test_ref="oval:org.mitre.oval:tst:3224"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win 2k3 SP1">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of Mshtml.dll is less than 6.0.3790.2920" test_ref="oval:org.mitre.oval:tst:3899"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win 2k3 SP2">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of Mshtml.dll is less than 6.0.3790.4064" test_ref="oval:org.mitre.oval:tst:3773"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win XP SP2 (64-bit)">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of Mshtml.dll is less than 6.0.3790.4064" test_ref="oval:org.mitre.oval:tst:3773"/>
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win XP SP1 (64-bit)">
          <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of Mshtml.dll is less than 6.0.3790.2920" test_ref="oval:org.mitre.oval:tst:3899"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1385" version="3" class="vulnerability">
      <metadata>
        <title>GDI Invalid Window Size Elevation of Privilege Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5586" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5586"/>
        <description>The Graphics Rendering Engine in Microsoft Windows 2000 SP4 and XP SP2 allows local users to gain privileges via "invalid application window sizes" in layered application windows, aka the "GDI Invalid Window Size Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2007-04-09T09:49:32">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-04-09T11:20:00.000-05:00">DRAFT</status_change>
            <status_change date="2007-04-25T19:52:16.301-04:00">INTERIM</status_change>
            <modified comment="Removed criteria sections and affected.platform elements for S03 and Vista. MS07-017 says they are not affected." date="2007-04-26T14:31:00.286-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-05-23T15:05:28.019-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1385 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:04:37.535-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:10.217-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="gdi32.dll version is less than 5.0.2195.7133" test_ref="oval:org.mitre.oval:tst:3337"/>
        </criteria>
        <criteria operator="AND" comment="Windows XP SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="gdi32.dll version is less than 5.1.2600.3099" test_ref="oval:org.mitre.oval:tst:3215"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:13796" version="7" class="vulnerability">
      <metadata>
        <title>Stack-based buffer overflow in assr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via crafted tag data in an Applix spreadsheet attachment, aka SPR PRAD8823A7.</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Lotus Notes</product>
        </affected>
        <reference ref_id="CVE-2011-1216" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1216" source="CVE"/>
        <description>Stack-based buffer overflow in assr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via crafted tag data in an Applix spreadsheet attachment, aka SPR PRAD8823A7.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-12-16T09:51:49.000-05:00">
              <contributor organization="DTCC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2011-12-19T15:44:14.657-05:00">DRAFT</status_change>
            <status_change date="2012-01-09T04:00:06.377-05:00">INTERIM</status_change>
            <status_change date="2012-01-30T04:00:22.085-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.altx-soft.oval:ste:18430 - contains tests with modified comments and all dependences" date="2014-02-13T12:19:00.287-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:22:42.073-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:00:40.043-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:13796 - registry_tests replaced with file_tests because registry path was compared with version" date="2015-05-29T11:02:00.629-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-05-29T11:05:02.339-04:00">INTERIM</status_change>
            <status_change date="2015-06-15T04:00:07.569-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Determine if the version of Lotus Notes is less than or equal to 8.5.2.2 and is greater than or equal to 8.0.0">
          <extend_definition comment="IBM Lotus Notes is installed" definition_ref="oval:org.mitre.oval:def:11999"/>
          <criterion comment="Determine if the version of Lotus Notes is less than or equal to 8.5.2.2" test_ref="oval:org.mitre.oval:tst:138913"/>
          <criterion comment="Determine if the version of Lotus Notes is greater than or equal to 8.0.0" test_ref="oval:org.mitre.oval:tst:138507"/>
        </criteria>
        <criteria operator="AND" comment="Determine if the version of Lotus Notes is less than or equal to 7.0.4 and is greater than or equal to 7.0.0">
          <extend_definition comment="IBM Lotus Notes is installed" definition_ref="oval:org.mitre.oval:def:11999"/>
          <criterion comment="Determine if the version of Lotus Notes is less than or equal to 7.0.4" test_ref="oval:org.mitre.oval:tst:138653"/>
          <criterion comment="Determine if the version of Lotus Notes is greater than or equal to 7.0.0" test_ref="oval:org.mitre.oval:tst:138900"/>
        </criteria>
        <criteria operator="AND" comment="Determine if the version of Lotus Notes is less than or equal to 6.5.6 and is greater than or equal to 6.0.1">
          <extend_definition comment="IBM Lotus Notes is installed" definition_ref="oval:org.mitre.oval:def:11999"/>
          <criterion comment="Determine if the version of Lotus Notes is less than or equal to 6.5.6" test_ref="oval:org.mitre.oval:tst:138776"/>
          <criterion comment="Determine if the version of Lotus Notes is greater than or equal to 6.0.1" test_ref="oval:org.mitre.oval:tst:138813"/>
        </criteria>
        <criteria operator="AND" comment="Determine if the version of Lotus Notes is less than or equal to 5.2 and is greater than or equal to 5:0a">
          <extend_definition comment="IBM Lotus Notes is installed" definition_ref="oval:org.mitre.oval:def:11999"/>
          <criterion comment="Determine if the version of Lotus Notes is less than or equal to 5.2" test_ref="oval:org.mitre.oval:tst:138910"/>
          <criterion comment="Determine if the version of Lotus Notes is greater than or equal to 5:0a" test_ref="oval:org.mitre.oval:tst:138741"/>
        </criteria>
        <criteria operator="AND" comment="Determine if the version of Lotus Notes is less than or equal to 4.6 and is greater than or equal to 4.2.1">
          <extend_definition comment="IBM Lotus Notes is installed" definition_ref="oval:org.mitre.oval:def:11999"/>
          <criterion comment="Determine if the version of Lotus Notes is less than or equal to 4.6" test_ref="oval:org.mitre.oval:tst:138685"/>
          <criterion comment="Determine if the version of Lotus Notes is greater than or equal to 4.2.1" test_ref="oval:org.mitre.oval:tst:138657"/>
        </criteria>
        <criteria operator="AND" comment="Determine if the version of Lotus Notes is less than or equal to 3.0.0.2 and is greater than or equal to 3.0.0.1">
          <extend_definition comment="IBM Lotus Notes is installed" definition_ref="oval:org.mitre.oval:def:11999"/>
          <criterion comment="Determine if the version of Lotus Notes is less than or equal to 3.0.0.2" test_ref="oval:org.mitre.oval:tst:138223"/>
          <criterion comment="Determine if the version of Lotus Notes is greater than or equal to 3.0.0.1" test_ref="oval:org.mitre.oval:tst:138612"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11999" version="3" class="inventory">
      <metadata>
        <title>IBM Lotus Notes is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>IBM Lotus Notes</product>
        </affected>
        <reference ref_id="cpe:/a:ibm:lotus_notes" source="CPE"/>
        <description>IBM Lotus Notes is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2011-02-25T20:15:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-02-28T09:39:49.571-05:00">DRAFT</status_change>
            <status_change date="2011-03-21T04:00:04.256-04:00">INTERIM</status_change>
            <status_change date="2011-04-11T04:00:04.578-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if IBM Lotus Notes is installed" test_ref="oval:org.mitre.oval:tst:41876"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1371" class="vulnerability" version="2">
      <metadata>
        <title>Outlook Web Access Script Injection Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Exchange Server</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0220" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0220"/>
        <description>Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2000 SP3, and 2003 SP1 and SP2 allows remote attackers to execute arbitrary scripts, spoof content, or obtain sensitive information via certain UTF-encoded, script-based e-mail attachments, involving an "incorrectly handled UTF character set label".</description>
        <oval_repository>
          <dates>
            <submitted date="2007-05-09T10:04:48">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-05-09T12:53:06-04:00">DRAFT</status_change>
            <status_change date="2007-05-31T15:26:32.784-04:00">INTERIM</status_change>
            <status_change date="2007-06-15T11:07:34.618-04:00">ACCEPTED</status_change>
            <modified comment="References registry value for Common Files directory due to multilingual support" date="2008-04-14T11:07:00.679-04:00">
              <contributor organization="GFI Software">Clifford Farrugia</contributor>
            </modified>
            <status_change date="2008-04-14T12:26:45.813-04:00">INTERIM</status_change>
            <status_change date="2008-05-05T04:00:09.995-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Microsoft Exchange 2000 Server Service Pack 3" operator="AND">
          <extend_definition comment="Microsoft Exchange 2000 Server Service Pack 3 is installed" definition_ref="oval:org.mitre.oval:def:1858"/>
          <criterion comment="the version of Cdoex.dll is less than 6.0.6619.12" test_ref="oval:org.mitre.oval:tst:3975"/>
        </criteria>
        <criteria comment="Microsoft Exchange Server 2003 Service Pack 1" operator="AND">
          <extend_definition comment="Microsoft Exchange Server 2003 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:1672"/>
          <criterion comment="the version of Cdoex.dll is less than 6.5.7235.2" test_ref="oval:org.mitre.oval:tst:3925"/>
        </criteria>
        <criteria comment="Microsoft Exchange Server 2003 Service Pack 2" operator="AND">
          <extend_definition comment="Microsoft Exchange Server 2003 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:1869"/>
          <criterion comment="the version of Cdoex.dll is less than 6.5.7652.24" test_ref="oval:org.mitre.oval:tst:3618"/>
        </criteria>
        <criteria comment="Microsoft Exchange Server 2007" operator="AND">
          <extend_definition comment="Microsoft Exchange Server 2007 is installed" definition_ref="oval:org.mitre.oval:def:1641"/>
          <criterion comment="the version of Cdoex.dll is less than 8.0.709.0" test_ref="oval:org.mitre.oval:tst:4122"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1869" version="6" class="inventory">
      <metadata>
        <title>Microsoft Exchange Server 2003 Service Pack 2 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Exchange Server 2003</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:exchange_server:2003:sp2"/>
        <description>Exchange Server 2003 SP2 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-05-09T10:04:48">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-05-09T12:53:06-04:00">DRAFT</status_change>
            <status_change date="2007-05-31T15:26:36.384-04:00">INTERIM</status_change>
            <status_change date="2007-06-15T11:07:36.442-04:00">ACCEPTED</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.345-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-10-25T16:48:05.799-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:01:03.015-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1869 - Updated CPEs for Microsoft Exchange Server." date="2011-03-29T13:58:00.209-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-03-29T13:58:51.723-04:00">INTERIM</status_change>
            <status_change date="2011-04-18T04:00:35.205-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:02.087-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:02.087-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:02:58.827-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Exchange Server 2003,SP2 is installed." test_ref="oval:org.mitre.oval:tst:1202"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1858" version="4" class="inventory">
      <metadata>
        <title>Microsoft Exchange Server 2000 Service Pack 3 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:exchange_server:2000:sp3"/>
        <description>Exchange Server 2000SP3 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-05-09T10:04:48">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-05-09T12:53:06-04:00">DRAFT</status_change>
            <status_change date="2007-05-31T15:26:36.002-04:00">INTERIM</status_change>
            <status_change date="2007-06-15T11:07:36.100-04:00">ACCEPTED</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.427-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-10-25T16:50:41.823-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:01:02.829-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1858 - Updated CPEs for Microsoft Exchange Server." date="2011-03-29T13:58:00.209-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-03-29T13:58:53.580-04:00">INTERIM</status_change>
            <status_change date="2011-04-18T04:00:34.580-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Exchange Server 2000,SP3 is installed." test_ref="oval:org.mitre.oval:tst:992"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1672" version="4" class="inventory">
      <metadata>
        <title>Microsoft Exchange Server 2003 Service Pack 1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:exchange_server:2003:sp1"/>
        <description>Exchange Server 2003 SP1 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-05-09T10:04:48">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-05-09T12:53:06-04:00">DRAFT</status_change>
            <status_change date="2007-05-31T15:26:34.555-04:00">INTERIM</status_change>
            <status_change date="2007-06-15T11:07:35.265-04:00">ACCEPTED</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.055-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-10-25T16:50:01.619-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:01:01.150-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1672 - Updated CPEs for Microsoft Exchange Server." date="2011-03-29T13:58:00.209-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-03-29T13:58:53.101-04:00">INTERIM</status_change>
            <status_change date="2011-04-18T04:00:34.286-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Exchange Server 2003,SP1 is installed." test_ref="oval:org.mitre.oval:tst:1108"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1641" version="5" class="inventory">
      <metadata>
        <title>Microsoft Exchange Server 2007 (no Service Pack) is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:exchange_server:2007:gold"/>
        <description>Exchange Server 2007 (no Service Pack) is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-05-09T10:04:48">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-05-09T12:53:06-04:00">DRAFT</status_change>
            <status_change date="2007-05-31T15:26:34.310-04:00">INTERIM</status_change>
            <status_change date="2007-06-15T11:07:35.112-04:00">ACCEPTED</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.621-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-10-25T16:51:06.842-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:01:00.696-05:00">ACCEPTED</status_change>
            <modified comment="The method it was using to check for lack of a service pack is not valid for Exchange 2007." date="2008-07-11T11:14:00.045-04:00">
              <contributor organization="Secure Elements, Inc.">Jeff Ito</contributor>
            </modified>
            <status_change date="2008-07-11T11:18:44.060-04:00">INTERIM</status_change>
            <status_change date="2008-07-28T04:00:05.662-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1641 - Updated CPEs for Microsoft Exchange Server." date="2011-03-29T13:58:00.209-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-03-29T13:58:54.126-04:00">INTERIM</status_change>
            <status_change date="2011-04-18T04:00:33.435-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Exchange Server 2007 is installed." test_ref="oval:org.mitre.oval:tst:8521"/>
        <criterion comment="No Exchange Server 2007 SP is installed." test_ref="oval:org.mitre.oval:tst:8498"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:136" version="1" class="vulnerability">
      <metadata>
        <title>Microsoft Java Virtual Machine Security Bypass</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Virtual Machine (VM)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0111" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0111"/>
        <description>The ByteCode Verifier component of Microsoft Virtual Machine (VM) build 5.0.3809 and earlier, as used in Windows and Internet Explorer, allows remote attackers to bypass security checks and execute arbitrary code via a malicious Java applet, aka "Flaw in Microsoft VM Could Enable System Compromise."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the version of msjava.dll is less than 5.0.3810.0" negate="false" test_ref="oval:org.mitre.oval:tst:2898"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1352" class="vulnerability" version="1">
      <metadata>
        <title>Windows Media Player Code Execution Vulnerability Decompressing Skins</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Windows Media Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3035" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3035"/>
        <description>Unspecified vulnerability in Microsoft Windows Media Player 7.1, 9, 10, and 11 allows remote attackers to execute arbitrary code via a skin file (WMZ or WMD) with crafted header information that is not properly handled during decompression, aka "Windows Media Player Code Execution Vulnerability Decompressing Skins."</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-15T09:28:35">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-08-15T15:55:12.887-04:00">DRAFT</status_change>
            <modified comment="Added version datatype to file_state version element. Altered oval:org.mitre.oval:ste:3362" date="2007-08-23T14:13:00.780-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="Added version datatype to file_state version element. Altered oval:org.mitre.oval:ste:3268" date="2007-08-23T14:13:00.640-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="Added version datatype to file_state version element. Altered oval:org.mitre.oval:ste:3208" date="2007-08-23T14:13:00.697-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="Added version datatype to file_state version element. Altered oval:org.mitre.oval:ste:3715" date="2007-08-23T14:13:00.054-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="Added version datatype to file_state version element. Altered oval:org.mitre.oval:ste:3766" date="2007-08-23T14:13:00.128-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="Added version datatype to file_state version element. Altered oval:org.mitre.oval:ste:3810" date="2007-08-23T14:13:00.388-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <modified comment="Added version datatype to file_state version element. Altered oval:org.mitre.oval:ste:3500" date="2007-08-23T14:13:00.056-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-09-10T14:45:25.733-04:00">INTERIM</status_change>
            <status_change date="2007-09-27T08:57:39.760-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Media Player v7.10">
          <extend_definition comment="Windows Media Player v7.1 is installed" definition_ref="oval:org.mitre.oval:def:1386"/>
          <criterion test_ref="oval:org.mitre.oval:tst:4149" comment="the version of Wmpui.dll is less than 7.10.0.3080"/>
        </criteria>
        <criteria comment="Media Player v9">
          <extend_definition comment="Windows Media Player v9 is installed" definition_ref="oval:org.mitre.oval:def:2147"/>
          <criterion test_ref="oval:org.mitre.oval:tst:3271" comment="the version of Wmp.dll is less than 9.0.0.3354"/>
        </criteria>
        <criteria comment="Media Player v10 on XP">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Windows Media Player v10 is installed" definition_ref="oval:org.mitre.oval:def:2172"/>
          <criterion test_ref="oval:org.mitre.oval:tst:4138" comment="the version of Wmp.dll is less than 10.0.0.4058"/>
        </criteria>
        <criteria comment="Media Player v11 on XP">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Windows Media Player v11 is installed" definition_ref="oval:org.mitre.oval:def:2126"/>
          <criterion test_ref="oval:org.mitre.oval:tst:4010" comment="the version of Wmp.dll is less than 11.0.5721.5230"/>
        </criteria>
        <criteria comment="Media Player v10 on S03,SP1">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2003 (x86) SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) SP1 is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP1 is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
          </criteria>
          <extend_definition comment="Windows Media Player v10 is installed" definition_ref="oval:org.mitre.oval:def:2172"/>
          <criterion test_ref="oval:org.mitre.oval:tst:3305" comment="the version of Wmp.dll is less than 10.0.0.3709"/>
        </criteria>
        <criteria comment="Media Player v10 on S03,SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows Server 2003 (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <extend_definition comment="Windows Media Player v10 is installed" definition_ref="oval:org.mitre.oval:def:2172"/>
          <criterion test_ref="oval:org.mitre.oval:tst:3348" comment="the version of Wmp.dll is less than 10.0.0.3998"/>
        </criteria>
        <criteria comment="Media Player v11 on Vista">
          <extend_definition comment="Microsoft Windows Vista is installed" definition_ref="oval:org.mitre.oval:def:228"/>
          <extend_definition comment="Windows Media Player v11 is installed" definition_ref="oval:org.mitre.oval:def:2126"/>
          <criterion test_ref="oval:org.mitre.oval:tst:3397" comment="the version of Wmp.dll is less than 11.0.6000.6336"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2172" version="9" class="inventory">
      <metadata>
        <title>Windows Media Player v10 is installed.</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Windows Media Player 10</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:windows_media_player:10"/>
        <description>Windows Media Player v10 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-15T09:28:35">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-08-15T15:55:11.378-04:00">DRAFT</status_change>
            <status_change date="2007-09-06T09:13:31.729-04:00">INTERIM</status_change>
            <status_change date="2007-09-27T08:57:45.569-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2172 - Modifications vary from minor OVAL title/description changes to suggesting an alternative CPE name to use." date="2011-09-28T11:29:00.976-04:00">
              <contributor organization="The MITRE Corporation">David Rothenberg</contributor>
            </modified>
            <status_change date="2011-09-28T11:33:32.988-04:00">INTERIM</status_change>
            <status_change date="2011-10-17T04:00:16.919-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:746 - added trailing $ to regexs" date="2011-10-31T09:26:00.646-04:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2011-10-31T09:31:18.161-04:00">INTERIM</status_change>
            <status_change date="2011-11-21T04:13:09.298-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2172 - inventory for Windows Media Player 10" date="2013-09-13T13:48:00.518-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-09-13T13:49:22.528-04:00">INTERIM</status_change>
            <status_change date="2013-09-30T04:01:18.940-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2172 - Modified Win Media Player inventories: Fixed product version info" date="2015-04-10T10:03:00.585-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-04-10T10:05:26.003-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:10.403-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Check if Windows Media Player version is greater than or equal to 10.0.0.0" test_ref="oval:org.mitre.oval:tst:86658"/>
        <criterion comment="Check if Windows Media Player version is less than 11.0.0.0" test_ref="oval:org.mitre.oval:tst:86603"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2147" version="11" class="inventory">
      <metadata>
        <title>Windows Media Player v9 is installed.</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Windows Media Player 9</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:windows_media_player:9"/>
        <description>Windows Media Player v9 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-15T09:28:35">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-08-15T15:55:11.096-04:00">DRAFT</status_change>
            <status_change date="2007-09-06T09:13:31.363-04:00">INTERIM</status_change>
            <status_change date="2007-09-27T08:57:45.263-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2147 - Modifications vary from minor OVAL title/description changes to suggesting an alternative CPE name to use." date="2011-09-28T11:29:00.976-04:00">
              <contributor organization="The MITRE Corporation">David Rothenberg</contributor>
            </modified>
            <status_change date="2011-09-28T11:33:37.426-04:00">INTERIM</status_change>
            <status_change date="2011-10-17T04:00:16.606-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:746 - added trailing $ to regexs" date="2011-10-31T09:26:00.646-04:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2011-10-31T09:31:18.431-04:00">INTERIM</status_change>
            <status_change date="2011-11-21T04:13:08.945-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2147 - inventory for Windows Media Player 9" date="2013-09-13T13:46:00.232-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-09-13T13:48:00.391-04:00">INTERIM</status_change>
            <status_change date="2013-09-30T04:01:18.559-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:86573 - replaced all similar objects with oval:org.mitre.oval:obj:26224" date="2014-04-10T08:55:00.661-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-04-10T08:58:19.904-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:00:10.909-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2147 - Modified Win Media Player inventories: Fixed product version info" date="2015-04-10T10:03:00.585-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-04-10T10:05:27.374-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:10.172-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Check if Windows Media Player version is greater than or equal to 9.0.0.0" test_ref="oval:org.mitre.oval:tst:86573"/>
        <criterion comment="Check if Windows Media Player version is less than 10.0.0.0" test_ref="oval:org.mitre.oval:tst:86682"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2126" version="11" class="inventory">
      <metadata>
        <title>Windows Media Player v11 is installed.</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Windows Media Player 11</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:windows_media_player:11"/>
        <description>Windows Media Player v11 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-15T09:28:35">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-08-15T15:55:11.057-04:00">DRAFT</status_change>
            <status_change date="2007-09-06T09:13:31.049-04:00">INTERIM</status_change>
            <status_change date="2007-09-27T08:57:44.929-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:2581 - On definition oval:org.mitre.oval:def:7384  I changed the affected platform from &quot;Microsoft Windows 2008&quot; to &quot;Microsoft Windows Server 2008&quot;" date="2011-05-12T10:52:00.860-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2011-05-12T10:58:12.639-04:00">INTERIM</status_change>
            <status_change date="2011-05-30T04:00:53.060-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2126 - Modifications vary from minor OVAL title/description changes to suggesting an alternative CPE name to use." date="2011-09-28T11:29:00.976-04:00">
              <contributor organization="The MITRE Corporation">David Rothenberg</contributor>
            </modified>
            <status_change date="2011-09-28T11:33:42.382-04:00">INTERIM</status_change>
            <status_change date="2011-10-17T04:00:16.259-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2126 - inventory for Windows Media Player 11" date="2013-09-13T13:49:00.798-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-09-13T13:51:09.932-04:00">INTERIM</status_change>
            <status_change date="2013-09-30T04:01:17.578-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:86659 - replaced all similar objects with oval:org.mitre.oval:obj:26224" date="2014-04-10T08:55:00.661-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-04-10T08:58:20.096-04:00">INTERIM</status_change>
            <status_change date="2014-04-28T04:00:10.276-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2126 - Modified Win Media Player inventories: Fixed product version info" date="2015-04-10T10:03:00.585-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-04-10T10:05:26.307-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:09.811-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Check if Windows Media Player version is greater than or equal to 11.0.0.0" test_ref="oval:org.mitre.oval:tst:86659"/>
        <criterion comment="Check if Windows Media Player version is less than 12.0.0.0" test_ref="oval:org.mitre.oval:tst:86623"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1386" version="9" class="inventory">
      <metadata>
        <title>Windows Media Player v7.1 is installed.</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows Media Player 7.1</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:windows_media_player:7.1"/>
        <description>Windows Media Player v7.1 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-15T09:28:35">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-08-15T15:55:10.760-04:00">DRAFT</status_change>
            <status_change date="2007-09-06T09:13:27.131-04:00">INTERIM</status_change>
            <status_change date="2007-09-27T08:57:40.144-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1386 - Modifications vary from minor OVAL title/description changes to suggesting an alternative CPE name to use." date="2011-09-28T11:29:00.976-04:00">
              <contributor organization="The MITRE Corporation">David Rothenberg</contributor>
            </modified>
            <status_change date="2011-09-28T11:33:45.235-04:00">INTERIM</status_change>
            <status_change date="2011-10-17T04:00:11.649-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:952 - def:5942 &amp; def:5689, Enhanced to cover WinVista, 2008, 2003 &amp; also 64-bit with service packs" date="2011-11-15T14:56:00.873-05:00">
              <contributor organization="SecPod Technologies">Pradeep R B</contributor>
            </modified>
            <status_change date="2011-11-15T14:58:49.482-05:00">INTERIM</status_change>
            <status_change date="2011-12-05T04:00:19.532-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:952 - Updated series of States to escape .(period) character." date="2012-01-13T17:30:00.463-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-01-13T17:34:55.237-05:00">INTERIM</status_change>
            <status_change date="2012-01-30T04:00:23.676-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1386 - Modified Win Media Player inventories: Fixed product version info" date="2015-04-10T10:03:00.585-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-04-10T10:05:27.195-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:06.265-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Windows Media Player 7.1 is installed" test_ref="oval:org.mitre.oval:tst:1066"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:134" version="5" class="vulnerability">
      <metadata>
        <title>Windows Script Engine Heap Overflow (Test 4)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows Script Engine for Jscript</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0010" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0010"/>
        <description>Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows operating system allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail that uses a large array index value that enables a heap-based buffer overflow attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-11-02T12:00:00.000-04:00"/>
            <status_change date="2004-11-03T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-12-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-01-06T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-06-08T03:17:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-29T06:49:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-07-03T12:56:00.000-04:00" comment="Added negate=true attribute to criteria sub-block to fix conversion error from OVAL 4.2 to OVAL 5.0">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-07-03T12:56:00.000-04:00">INTERIM</status_change>
            <modified date="2006-09-06T15:59:00.000-04:00" comment="changed criteria operator to OR when checking file version and patch installation">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2006-09-27T12:28:40.970-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:134 - Consolidated def:200, 794, and 795 into def:134." date="2011-01-13T14:16:00.023-05:00">
              <contributor organization="The MITRE Corporation">Nate Przybyszewski</contributor>
            </modified>
            <status_change date="2011-01-13T14:17:24.364-05:00">INTERIM</status_change>
            <status_change date="2011-01-31T04:00:13.534-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="detected unpatched jscript.dll v5.1">
          <criterion comment="Jscript.dll for JScript 5.1 or later is installed" test_ref="oval:org.mitre.oval:tst:10504"/>
          <criterion comment="the version of jscript.dll is less than 5.1.0.8513" test_ref="oval:org.mitre.oval:tst:2907"/>
        </criteria>
        <criteria operator="AND" comment="detected unpatched jscript.dll v5.5">
          <criterion comment="the version of Jscript.dll is greater than or equal to 5.5.0.0" test_ref="oval:org.mitre.oval:tst:42062"/>
          <criterion comment="the version of jscript.dll is less than 5.5.0.8513" test_ref="oval:org.mitre.oval:tst:2906"/>
        </criteria>
        <criteria operator="AND" comment="detected unpatched jscript.dll v5.6">
          <criterion comment="the version of Jscript.dll is greater than or equal to 5.6.0.0" test_ref="oval:org.mitre.oval:tst:719"/>
          <criterion comment="the version of jscript.dll is less than 5.6.0.8513" test_ref="oval:org.mitre.oval:tst:2905"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1338" version="4" class="vulnerability">
      <metadata>
        <title>TIP Request Validation Process Permits Denial of Service (Win2k,SP4)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>TIP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1979" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1979"/>
        <description>Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service exception and exit) via an "unexpected protocol command during the reconnection request," which is not properly handled by the Transaction Internet Protocol (TIP) functionality.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:56.417-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:00:53.864-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="Win2K/XP/2003 service pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2569"/>
        <criteria operator="OR" comment="Either ole32.dll or rpcss.dll has a version less than 5.0.2195.7059">
          <criterion comment="the version of ole32.dll is less than 5.0.2195.7059" negate="false" test_ref="oval:org.mitre.oval:tst:2568"/>
          <criterion comment="the version of rpcss.dll is less than 5.0.2195.7059" negate="false" test_ref="oval:org.mitre.oval:tst:2567"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1337" version="5" class="vulnerability">
      <metadata>
        <title>IE5.01,SP4 COM Object Instantiation Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1990" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1990"/>
        <description>Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not ActiveX controls, including (1) devenum.dll, (2) diactfrm.dll, (3) wmm2filt.dll, (4) fsusd.dll, (5) dmdskmgr.dll, (6) browsewm.dll, (7) browseui.dll, (8) shell32.dll, (9) mshtml.dll, (10) inetcfg.dll, (11) infosoft.dll, (12) query.dll, (13) syncui.dll, (14) clbcatex.dll, (15) clbcatq.dll, (16) comsvcs.dll, and (17) msconf.dll, which causes memory corruption, aka "COM Object Instantiation Memory Corruption Vulnerability," a different vulnerability than CVE-2005-2087.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-23T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-08-25T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed reference to patch kb896727 from criteria">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed ste:2614: set datatype to version.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:54:00.319-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:59:42.633-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:41.634-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:50.012-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:15.136-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3831.1800" negate="false" test_ref="oval:org.mitre.oval:tst:2664"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1336" version="9" class="vulnerability">
      <metadata>
        <title>IE6 Address Bar Spoofing Vulnerability (Win2K/XP,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1192" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1192"/>
        <description>Microsoft Internet Explorer 5.01 through 6 allows remote attackers to conduct phishing attacks by spoofing the address bar and other parts of the trust UI via unknown methods that allow "window content to persist" after the user has navigated to another site, aka the "Address Bar Spoofing Vulnerability."  NOTE: this is a different vulnerability than CVE-2006-1626.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added an anchor to the regex used to check for Internet Explorer 6." date="2007-01-11T20:38:00.950-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-01-11T20:49:14.285-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:41.423-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:2185 - Anchored regular expression" date="2011-02-22T12:51:00.261-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:52:34.659-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:00:46.534-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:55.805-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:00:53.326-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:49.842-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:14.913-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Win2K or XP,SP1 is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="Internet Explorer 6 (any patch level) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2333"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2800.1543" negate="false" test_ref="oval:org.mitre.oval:tst:2332"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:13344" version="3" class="vulnerability">
      <metadata>
        <title>HTML Objects Memory Corruption Vulnerability in Internet Explorer</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 5.01</product>
          <product>Microsoft Internet Explorer 6</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3476" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3476"/>
        <description>Microsoft Internet Explorer 5.01 SP4 and 6 does not properly handle errors associated with access to uninitialized memory, which allows remote attackers to execute arbitrary code via a crafted HTML document, aka "HTML Objects Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2011-10-25T13:27:14">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-10-28T20:26:16.136-04:00">DRAFT</status_change>
            <status_change date="2011-11-14T04:00:18.782-05:00">INTERIM</status_change>
            <status_change date="2011-12-05T04:00:18.516-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 5.01 SP4 and Win 2K">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="Mshtml.dll version is less than 5.0.3868.2000" test_ref="oval:org.mitre.oval:tst:9144"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 and Win 2KSo4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1615" test_ref="oval:org.mitre.oval:tst:8845"/>
        </criteria>
        <criteria operator="AND" comment="Win XP SP2 X86 and IE6">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3429" test_ref="oval:org.mitre.oval:tst:9320"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
        </criteria>
        <criteria operator="AND" comment="Win XP SP2 X86 and IE6">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5659" test_ref="oval:org.mitre.oval:tst:9099"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
        </criteria>
        <criteria operator="AND" comment="IE6 and Win 2K3 SP1 or Win XP X64 SP1">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.3194" test_ref="oval:org.mitre.oval:tst:8956"/>
          <criteria operator="OR" comment="Win XP X64 SP1 or Win 2K3 SP1">
            <extend_definition comment="Microsoft Windows XP Professional x64 Edition SP1 is installed" definition_ref="oval:org.mitre.oval:def:720"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:4386"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 2K3 SP2 or Win XP X64 SP2 and IE6">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4357" test_ref="oval:org.mitre.oval:tst:8902"/>
          <criteria operator="OR" comment="Win 2K3 SP2 or Win XP X64 Sp2">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1332" version="8" class="vulnerability">
      <metadata>
        <title>Windows 2000 Certificate Validation Identity Spoofing Vulnerability (Test 1)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Certificate Validation</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0862" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0862"/>
        <description>The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for Mac, do not properly verify the Basic Constraints of intermediate CA-signed X.509 certificates, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack for SSL sessions, as originally reported for Internet Explorer and IIS.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <modified date="2004-07-13T12:00:00.000-04:00" comment="Added superceding patch info.">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2004-07-14T12:00:00.000-04:00" comment="Changed to DRAFT">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-08-04T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-03-07T12:00:00.000-04:00" comment="modified wrt-222 - changed pattern match">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-29T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-06-08T03:17:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-29T06:49:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Multiple corrections and update to POSIX compatibility for ste:2878" date="2010-11-29T16:13:00.904-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-11-29T16:14:05.554-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:32.671-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:57.090-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:00:52.883-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="SP4 or later Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3073"/>
        </criteria>
        <criterion comment="the version of cryptdlg.dll is less than 5.0.1558.6608" negate="false" test_ref="oval:org.mitre.oval:tst:982"/>
        <criterion comment="the patch Q329115 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1231"/>
        <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1330" version="7" class="vulnerability">
      <metadata>
        <title>Windows 2000 IIS WebDAV Message Handler Denial of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0718" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0718"/>
        <description>The WebDAV Message Handler for Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows remote attackers to cause a denial of service (memory and CPU exhaustion, application crash) via a PROPFIND request with an XML message containing XML elements with a large number of attributes.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-13T09:30:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2004-10-13T01:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-10-27T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-11-17T10:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.950-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-10-25T16:50:55.656-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:00:58.541-05:00">ACCEPTED</status_change>
            <modified comment="Corrected and tightened regular expression in ste:2610" date="2010-12-02T11:46:00.307-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-12-02T11:47:27.969-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:32.316-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:53.552-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:00:52.485-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows 2000 (sp5 or earlier) is installed">
            <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
            <criterion comment="Win2K/XP/2003 service pack 5 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2790"/>
          </criteria>
          <criterion comment="the version of httpext.dll is less than 5.0.2195.6958" negate="false" test_ref="oval:org.mitre.oval:tst:985"/>
          <criterion comment="the patch KB824151 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:984"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="WebDav is disabled(for iis 5.0)" negate="true" test_ref="oval:org.mitre.oval:tst:2953"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:13299" version="8" class="vulnerability">
      <metadata>
        <title>Cross-Domain Information Disclosure Vulnerability in Internet Explorer</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3474" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3474"/>
        <description>Microsoft Internet Explorer 6 and 7 does not properly determine the domain or security zone of origin of web script, which allows remote attackers to bypass the intended cross-domain security policy and obtain sensitive information via a crafted HTML document, aka "Cross-Domain Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2011-10-25T13:27:14">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-10-28T20:26:15.058-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8644 - ste:4424 is updated to correct version. added 5 new definitions for ms08-058 are not in the repository" date="2011-10-28T20:15:00.656-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2011-11-14T04:00:17.957-05:00">INTERIM</status_change>
            <status_change date="2011-12-05T04:00:17.678-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4503 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:24:13.970-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:00:39.818-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:13299 - extended definitions of OS are without SP checks" date="2014-07-28T17:57:00.076-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:59:03.766-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:00:43.122-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 and Win 2KSo4">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1615" test_ref="oval:org.mitre.oval:tst:8845"/>
        </criteria>
        <criteria operator="AND" comment="Win XP X86 and IE6">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3429" test_ref="oval:org.mitre.oval:tst:9320"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
        </criteria>
        <criteria operator="AND" comment="Win XP X86 and IE6">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5659" test_ref="oval:org.mitre.oval:tst:9099"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
        </criteria>
        <criteria operator="AND" comment="IE7 and Win XP or Win 2K3">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="Win XP or Win 2K3">
            <extend_definition comment="Microsoft Windows XP is installed" definition_ref="oval:org.mitre.oval:def:105"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR / GDR">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16735" test_ref="oval:org.mitre.oval:tst:8577"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.20900" test_ref="oval:org.mitre.oval:tst:44256"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE6 and Win 2K3 or Win XP X64">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.3194" test_ref="oval:org.mitre.oval:tst:8956"/>
          <criteria operator="OR" comment="Win XP X64 or Win 2K3">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 2K3 or Win XP X64 and IE6">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4357" test_ref="oval:org.mitre.oval:tst:8902"/>
          <criteria operator="OR" comment="Win 2K3 or Win XP X64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE7 and Vista">
          <extend_definition comment="Microsoft Windows Vista is installed" definition_ref="oval:org.mitre.oval:def:228"/>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16757" test_ref="oval:org.mitre.oval:tst:8644"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.20927" test_ref="oval:org.mitre.oval:tst:9560"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 2K8 / Vista and IE7">
          <criteria operator="OR" comment="Win 2K8 / Vista">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR / GDR">
            <criterion comment="Mshtml.dll version is less than 7.0.6001.18148" test_ref="oval:org.mitre.oval:tst:9509"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Mshtml.dll version is greater than or equal to 7.0.6001.22000" test_ref="oval:org.mitre.oval:tst:42152"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6001.22260" test_ref="oval:org.mitre.oval:tst:9350"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
        </criteria>
        <criteria operator="AND" comment="Win 2K8 ia 64">
          <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          <criteria operator="OR" comment="Check for LDR / GDR">
            <criterion comment="Check if the version of mshtml.dll is less than 7.0.6001.18137" test_ref="oval:org.mitre.oval:tst:44400"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Mshtml.dll version is less than 7.0.6001.22260" test_ref="oval:org.mitre.oval:tst:9350"/>
              <criterion comment="Mshtml.dll version is greater than or equal to 7.0.6001.22000" test_ref="oval:org.mitre.oval:tst:42152"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1326" version="5" class="vulnerability">
      <metadata>
        <title>IE5.01,SP4 Java Proxy COM Object Instantiation Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2087" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2087"/>
        <description>Internet Explorer 5.01 SP4 up to 6 on various Windows operating systems, including IE 6.0.2900.2180 on Windows XP, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not ActiveX controls, as demonstrated using the JVIEW Profiler (Javaprxy.dll).  NOTE: the researcher says that the vendor could not reproduce this problem.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-18T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-08-25T04:00:00.000-04:00">DRAFT</status_change>
            <modified date="2005-09-08T04:00:00.000-04:00" comment="modified wet-2 - Corrected structure of path components.">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2005-09-28T01:05:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="This is fixed by MS05-038, which provides better test criteria. Changed test criteria accordingly.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed ste:2614: set datatype to version.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:54:00.319-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:59:41.881-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:40.859-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:47.430-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:14.351-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3831.1800" negate="false" test_ref="oval:org.mitre.oval:tst:2664"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:13255" version="8" class="vulnerability">
      <metadata>
        <title>Information disclosure vulnerability in Internet Explorer due to improper event-handling</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3473" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3473"/>
        <description>Microsoft Internet Explorer 6 and 7 does not properly determine the domain or security zone of origin of web script, which allows remote attackers to bypass the intended cross-domain security policy, and execute arbitrary code or obtain sensitive information, via a crafted HTML document, aka "Event Handling Cross-Domain Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2011-10-25T13:27:14">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-10-28T20:26:14.392-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8644 - ste:4424 is updated to correct version. added 5 new definitions for ms08-058 are not in the repository" date="2011-10-28T20:15:00.656-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2011-11-14T04:00:16.800-05:00">INTERIM</status_change>
            <status_change date="2011-12-05T04:00:15.669-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4503 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:24:14.296-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:00:39.523-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:13255 - extended definitions of OS are without SP checks" date="2014-07-28T17:57:00.076-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:59:05.211-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:00:42.614-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 and Win 2KSo4">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1615" test_ref="oval:org.mitre.oval:tst:8845"/>
        </criteria>
        <criteria operator="AND" comment="Win XP X86 and IE6">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3429" test_ref="oval:org.mitre.oval:tst:9320"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
        </criteria>
        <criteria operator="AND" comment="Win XP X86 and IE6">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5659" test_ref="oval:org.mitre.oval:tst:9099"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
        </criteria>
        <criteria operator="AND" comment="IE7 and Win XP or Win 2K3">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="Win XP or Win 2K3">
            <extend_definition comment="Microsoft Windows XP is installed" definition_ref="oval:org.mitre.oval:def:105"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR / GDR">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16735" test_ref="oval:org.mitre.oval:tst:8577"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.20900" test_ref="oval:org.mitre.oval:tst:44256"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE6 and Win 2K3 or Win XP X64">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.3194" test_ref="oval:org.mitre.oval:tst:8956"/>
          <criteria operator="OR" comment="Win XP X64 or Win 2K3">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 2K3 or Win XP X64 and IE6">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4357" test_ref="oval:org.mitre.oval:tst:8902"/>
          <criteria operator="OR" comment="Win 2K3 or Win XP X64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE7 and Vista">
          <extend_definition comment="Microsoft Windows Vista is installed" definition_ref="oval:org.mitre.oval:def:228"/>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16757" test_ref="oval:org.mitre.oval:tst:8644"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.20927" test_ref="oval:org.mitre.oval:tst:9560"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 2K8 / Vista and IE7">
          <criteria operator="OR" comment="Win 2K8 / Vista">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR / GDR">
            <criterion comment="Mshtml.dll version is less than 7.0.6001.18148" test_ref="oval:org.mitre.oval:tst:9509"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Mshtml.dll version is greater than or equal to 7.0.6001.22000" test_ref="oval:org.mitre.oval:tst:42152"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6001.22260" test_ref="oval:org.mitre.oval:tst:9350"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
        </criteria>
        <criteria operator="AND" comment="Win 2K8 ia 64">
          <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          <criteria operator="OR" comment="Check for LDR / GDR">
            <criterion comment="Check if the version of mshtml.dll is less than 7.0.6001.18137" test_ref="oval:org.mitre.oval:tst:44400"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Mshtml.dll version is less than 7.0.6001.22260" test_ref="oval:org.mitre.oval:tst:9350"/>
              <criterion comment="Mshtml.dll version is greater than or equal to 7.0.6001.22000" test_ref="oval:org.mitre.oval:tst:42152"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1316" version="1" class="vulnerability">
      <metadata>
        <title>Exchange Server 5.0 TNEF Decoding Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Outlook</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0002" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0002"/>
        <description>Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-11T12:56:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-12T09:25:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-01T09:08:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the version of Mdbmsg.dll greater than or equal 5.0.1460.9 (Exchange Server 5.0,SP2 is installed)." negate="false" test_ref="oval:org.mitre.oval:tst:990"/>
        <criterion comment="the version of Mdbmsg.dll is less than 5.0.1462.22" negate="false" test_ref="oval:org.mitre.oval:tst:989"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:13151" version="3" class="vulnerability">
      <metadata>
        <title>Uninitialized Memory Corruption Vulnerability in Internet Explorer</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 6</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3475" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3475"/>
        <description>Microsoft Internet Explorer 6 does not properly handle errors related to using the componentFromPoint method on xml objects that have been (1) incorrectly initialized or (2) deleted, which allows remote attackers to execute arbitrary code via a crafted HTML document, aka "Uninitialized Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2011-10-25T13:27:14">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-10-28T20:26:15.685-04:00">DRAFT</status_change>
            <status_change date="2011-11-14T04:00:13.549-05:00">INTERIM</status_change>
            <status_change date="2011-12-05T04:00:12.120-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 and Win 2KSo4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1615" test_ref="oval:org.mitre.oval:tst:8845"/>
        </criteria>
        <criteria operator="AND" comment="Win XP SP2 X86 and IE6">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3429" test_ref="oval:org.mitre.oval:tst:9320"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
        </criteria>
        <criteria operator="AND" comment="Win XP SP2 X86 and IE6">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5659" test_ref="oval:org.mitre.oval:tst:9099"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
        </criteria>
        <criteria operator="AND" comment="IE6 and Win 2K3 SP1 or Win XP X64 SP1">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.3194" test_ref="oval:org.mitre.oval:tst:8956"/>
          <criteria operator="OR" comment="Win XP X64 SP1 or Win 2K3 SP1">
            <extend_definition comment="Microsoft Windows XP Professional x64 Edition SP1 is installed" definition_ref="oval:org.mitre.oval:def:720"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:4386"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 2K3 SP2 or Win XP X64 SP2 and IE6">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4357" test_ref="oval:org.mitre.oval:tst:8902"/>
          <criteria operator="OR" comment="Win 2K3 SP2 or Win XP X64 Sp2">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:720" version="11" class="inventory">
      <metadata>
        <title>Microsoft Windows XP Professional x64 Edition SP1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_xp::sp1:x64"/>
        <description>A version of Microsoft Windows XP Professional x64 Edition Service Pack 1 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-03-05T09:00:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2007-03-05T09:00:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:17:24.909-04:00">INTERIM</status_change>
            <status_change date="2007-04-10T13:44:27.909-04:00">ACCEPTED</status_change>
            <modified comment="Changed the CPE reference" date="2008-04-04T11:17:00.527-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2008-04-04T11:28:52.548-04:00">INTERIM</status_change>
            <status_change date="2008-04-21T04:00:23.716-04:00">ACCEPTED</status_change>
            <modified comment="Removed Microsoft reference" date="2009-06-01T16:05:28.035-04:00">
              <contributor organization="The MITRE Corporation">Brendan Miles</contributor>
            </modified>
            <status_change date="2009-06-08T04:01:06.706-04:00">INTERIM</status_change>
            <status_change date="2009-06-29T04:01:10.364-04:00">ACCEPTED</status_change>
            <modified comment="Changed registry check for amd64 to be a case insensitive equals" date="2009-09-04T10:48:00.140-05:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2009-09-14T04:00:18.431-04:00">INTERIM</status_change>
            <status_change date="2009-10-05T04:00:06.883-04:00">ACCEPTED</status_change>
            <modified comment="Changed registry check for amd64 to be case insensitive equals" date="2009-11-19T18:33:00.593-05:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2009-11-19T18:35:10.152-05:00">INTERIM</status_change>
            <modified comment=" Changed the tests for SP1 and windows to be case insensitive and replaced the test for Windows 5.1 with a new test for Windows XP" date="2009-12-02T16:05:00.749-04:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:56:00.359-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <modified comment="Updating regex to include parenthesis" date="2009-12-08T17:32:00.792-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <status_change date="2010-01-04T04:01:55.866-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:44:35.612-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:03:24.234-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:3180 - new inventory for SQL Server 2008 R2 64-bit" date="2013-07-05T09:33:00.078-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-05T09:37:48.110-04:00">INTERIM</status_change>
            <status_change date="2013-07-22T04:03:11.990-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criterion comment="Windows XP is installed" test_ref="oval:org.mitre.oval:tst:11179"/>
        <criterion comment="a version of Windows for the x64 architecture is installed" test_ref="oval:org.mitre.oval:tst:3653"/>
        <criterion comment="Win2K/XP/2003/Vista service pack 1 is installed" test_ref="oval:org.mitre.oval:tst:2843"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4386" version="11" class="inventory">
      <metadata>
        <title>Microsoft Windows Server 2003 SP1 (x64) is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_2003_server::sp1:x64"/>
        <description>A version of Microsoft Windows Server 2003 SP1 (x64) is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-11-15T15:56:12">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-11-16T08:53:11.806-05:00">DRAFT</status_change>
            <status_change date="2007-12-03T04:06:45.400-05:00">INTERIM</status_change>
            <status_change date="2007-12-24T04:06:31.544-05:00">ACCEPTED</status_change>
            <modified comment="Changed the CPE reference" date="2008-04-04T11:17:00.620-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2008-04-04T11:21:37.641-04:00">INTERIM</status_change>
            <status_change date="2008-04-21T04:00:19.559-04:00">ACCEPTED</status_change>
            <modified comment="Changed registry check for amd64 to be case insensitive equals" date="2009-11-19T18:33:00.593-05:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2009-11-19T18:35:09.867-05:00">INTERIM</status_change>
            <modified comment="Changed the tests for SP1 and windows to be case insensitive and replaced the test for Windows 5.2 with a new test for 2003" date="2009-12-02T16:05:00.749-04:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:56:00.085-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <modified comment="Updating regex to include parenthesis" date="2009-12-08T17:31:00.354-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <status_change date="2010-01-04T04:01:31.908-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:4386 - Updated Windows 2003 Server CPE names." date="2011-03-29T13:48:00.699-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-03-29T13:51:30.669-04:00">INTERIM</status_change>
            <status_change date="2011-04-18T04:00:37.303-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:44:39.990-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:02:58.468-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:3180 - new inventory for SQL Server 2008 R2 64-bit" date="2013-07-05T09:33:00.078-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-05T09:37:56.404-04:00">INTERIM</status_change>
            <status_change date="2013-07-22T04:03:05.085-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criterion comment="Windows Server 2003 is installed" test_ref="oval:org.mitre.oval:tst:11145"/>
        <criterion comment="a version of Windows for the x64 architecture is installed" test_ref="oval:org.mitre.oval:tst:3653"/>
        <criterion comment="Win2K/XP/2003/Vista service pack 1 is installed" test_ref="oval:org.mitre.oval:tst:2843"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:13148" version="15" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in Oracle VM VirtualBox related to Guest Additions for Windows</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Oracle VirtualBox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2011-2300" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2300"/>
        <description>Unspecified vulnerability in Oracle VM VirtualBox 4.0 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Guest Additions for Windows.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-10-11T15:20:33.178-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </submitted>
            <status_change date="2011-10-17T13:06:24.137-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15629 - Found a few issues with the current inventory definition for VirtualBox and the vulnerability definition which uses it, and the fixes plus a bit more are attached. The core issue is that the registry key where the relevant information is stored has had 4 different values since version 3.0.0, with the most recent change causing the vulnerability definition to throw an error." date="2011-10-17T13:02:00.116-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-11-07T04:00:55.894-05:00">INTERIM</status_change>
            <status_change date="2011-11-28T04:00:32.967-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:13148 - Virtual Box Object fix." date="2013-04-26T15:19:00.059-04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2013-04-26T15:20:57.822-04:00">INTERIM</status_change>
            <status_change date="2013-05-13T04:00:04.978-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:13148 - modified vulnerabilities of Oracle Virtualbox (part 1)" date="2013-09-03T10:20:00.215-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-09-03T10:22:45.707-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:12025 - modified vulnerabilities of Oracle Virtualbox (part 3)" date="2013-09-03T10:59:00.280-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-09-23T04:00:07.493-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15297 - modificated vulnerabilities for VirtualBox" date="2013-12-05T10:43:00.197-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-05T10:45:12.122-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:00:15.302-05:00">ACCEPTED</status_change>
            <status_change date="2013-12-23T04:00:11.465-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:13148 - New vulnerability(CVE-2013-5892) added and modified existing criteria" date="2014-01-30T14:45:00.034-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-30T14:49:21.695-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:10.099-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="VirtualBox is installed" definition_ref="oval:org.mitre.oval:def:11581"/>
        <criterion comment="Check if Oracle VM VirtualBox is installed" test_ref="oval:org.mitre.oval:tst:42006"/>
        <criteria operator="AND" comment="Affected versions of VirtualBox">
          <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.0.0" test_ref="oval:org.mitre.oval:tst:88607"/>
          <criterion comment="Check if Oracle VM VirtualBox version is less than 4.1.0" test_ref="oval:org.mitre.oval:tst:100062"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1308" version="5" class="vulnerability">
      <metadata>
        <title>IE5.01,SP4 Security Zone Restriction Bypass Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0054" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0054"/>
        <description>Internet Explorer 5.01, 5.5, and 6 allows remote attackers to spoof a less restrictive security zone and execute arbitrary code via an HTML page containing URLs that contain hostnames that have been double hex encoded, which are decoded twice to generate a malicious hostname, aka the "URL Decoding Zone Spoofing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-03-23T08:09:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-13T12:15:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-05-04T12:33:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed test to check kb867282.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed ste:2614: set datatype to version.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:54:00.319-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:59:39.172-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:39.934-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:43.827-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:13.744-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3825.700" negate="false" test_ref="oval:org.mitre.oval:tst:994"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1307" version="3" class="vulnerability">
      <metadata>
        <title>Firefox/Mozilla Suite JavaScript Integer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2705" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2705"/>
        <description>Integer overflow in the JavaScript engine in Firefox before 1.0.7 and Mozilla Suite before 1.7.12 might allow remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-11T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-12T10:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:2367" date="2007-02-26T08:32:00.241-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-26T08:32:39.676-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:2370" date="2007-03-06T07:46:00.064-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:47.593-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:1444" date="2007-04-23T12:05:00.911-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:19:59.289-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:1445" date="2007-04-23T12:05:00.720-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:10:53.182-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Suite version 1.7.10 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.10 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2535"/>
          <criterion comment="Mozilla Suite version 1.7.10 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2534"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.6 or earlier is installed">
          <criterion comment="Firefox version 1.0.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2533"/>
          <criterion comment="Mozilla Firefox version 1.0.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2532"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:13040" version="3" class="vulnerability">
      <metadata>
        <title>Endless Loop DoS in snabase.exe Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Host Integration Server 2004</product>
          <product>Microsoft Host Integration Server 2006</product>
          <product>Microsoft Host Integration Server 2009</product>
          <product>Microsoft Host Integration Server 2010</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2011-2007" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2007"/>
        <description>Microsoft Host Integration Server (HIS) 2004 SP1, 2006 SP1, 2009, and 2010 allows remote attackers to cause a denial of service (SNA Server service outage) via crafted TCP or UDP traffic, aka "Endless Loop DoS in snabase.exe Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2011-10-11T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2011-10-17T09:26:40.283-04:00">DRAFT</status_change>
            <status_change date="2011-11-07T04:00:49.179-05:00">INTERIM</status_change>
            <status_change date="2011-11-28T04:00:23.557-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Microsoft Host Integration Server 2004 SP1">
          <extend_definition comment="Microsoft Host Integration Server 2004 SP1 is installed" definition_ref="oval:org.mitre.oval:def:5430"/>
          <criterion comment="Snadmod.dll version is less than 6.0.2445.0" test_ref="oval:org.mitre.oval:tst:43888"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Host Integration Server 2006">
          <extend_definition comment="Microsoft Host Integration Server 2006 is installed" definition_ref="oval:org.mitre.oval:def:5373"/>
          <criterion comment="Snadmod.dll version is less than 7.0.4220.0" test_ref="oval:org.mitre.oval:tst:44254"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Host Integration Server 2009">
          <extend_definition comment="Microsoft Host Integration Server 2009 is installed" definition_ref="oval:org.mitre.oval:def:12766"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Snadmod.dll version is less than 8.0.3850.1" test_ref="oval:org.mitre.oval:tst:44027"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Snadmod.dll version is less than 8.0.3872.2" test_ref="oval:org.mitre.oval:tst:43857"/>
              <criterion comment="Snadmod.dll version is greater than or equal to 8.0.3870.0" test_ref="oval:org.mitre.oval:tst:44243"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Microsoft Host Integration Server 2010">
          <extend_definition comment="Microsoft Host Integration Server 2010 is installed" definition_ref="oval:org.mitre.oval:def:12165"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Snadmod.dll version is less than 8.5.4317.1" test_ref="oval:org.mitre.oval:tst:44232"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Snadmod.dll version is less than 8.5.4369.2" test_ref="oval:org.mitre.oval:tst:44184"/>
              <criterion comment="Snadmod.dll version is greater than or equal to 8.5.4360.0" test_ref="oval:org.mitre.oval:tst:43281"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:130" version="7" class="vulnerability" deprecated="true">
      <metadata>
        <title>DEPRECATED: Windows 2000 HTR ISAPI Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0071" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0071"/>
        <description>Buffer overflow in the ism.dll ISAPI extension that implements HTR scripting in Internet Information Server (IIS) 4.0 and 5.0 allows attackers to cause a denial of service or execute arbitrary code via HTR requests with long variable names.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected to use a forward slash as the separator in the key." date="2007-05-07T15:59:00.150-04:00">
              <contributor organization="Secure Elements, Inc.">Glenn Strickland</contributor>
            </modified>
            <status_change date="2007-05-07T16:04:54.795-04:00">INTERIM</status_change>
            <status_change date="2007-05-23T15:05:27.002-04:00">ACCEPTED</status_change>
            <modified comment="Multiple corrections and update to POSIX compatibility for ste:2884" date="2010-11-29T16:14:00.692-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-11-29T16:14:39.209-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:31.897-05:00">ACCEPTED</status_change>
            <modified comment="Use def:12413 instead" date="2011-01-20T10:11:28.209-05:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-01-20T10:11:28.209-05:00">DEPRECATED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
          <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
          <criterion comment="the version of w3svc.dll is less than 5.0.2195.5269" negate="false" test_ref="oval:org.mitre.oval:tst:3080"/>
          <criterion comment="Patch Q319733 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3095"/>
          <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
          <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
          <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3079"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="ism.dll mapping exists" negate="false" test_ref="oval:org.mitre.oval:tst:3057"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:13" version="3" class="vulnerability">
      <metadata>
        <title>Buffer Overrun in HTML Help Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference ref_id="CVE-2006-3357" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3357" source="CVE"/>
        <description>Heap-based buffer overflow in HTML Help ActiveX control (hhctrl.ocx) in Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code by repeatedly setting the Image field of an Internet.HHCtrl.1 object to certain values, possibly related to improper escaping and long strings.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:28:38.073-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:57:21.058-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:13 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:06:36.096-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:09.767-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win2K,SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="The version of Hhctrl.ocx is less than 5.2.3790.558." test_ref="oval:org.mitre.oval:tst:44"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP1">
          <extend_definition comment="Microsoft Windows XP SP1 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          <criterion comment="The version of Hhctrl.ocx is less than 5.2.3790.558." test_ref="oval:org.mitre.oval:tst:44"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="The version of Hhctrl.ocx is less than 5.2.3790.2744." test_ref="oval:org.mitre.oval:tst:15"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP1 (64-bit)">
          <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="The version of Hhctrl.ocx is less than 5.2.3790.2744." test_ref="oval:org.mitre.oval:tst:15"/>
        </criteria>
        <criteria operator="AND" comment="S03-Gold">
          <extend_definition comment="Microsoft Windows Server 2003 (x86) Gold is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="The version of Hhctrl.ocx is less than 5.2.3790.558." test_ref="oval:org.mitre.oval:tst:44"/>
        </criteria>
        <criteria operator="AND" comment="S03,SP1">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="The version of Hhctrl.ocx is less than 5.2.3790.2744." test_ref="oval:org.mitre.oval:tst:15"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12983" version="13" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in Oracle VM VirtualBox</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Oracle VirtualBox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2011-2305" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2305"/>
        <description>Unspecified vulnerability in Oracle VM VirtualBox 3.0, 3.1, 3.2, and 4.0 allows local users to affect confidentiality, integrity, and availability via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-10-11T15:20:33.178-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </submitted>
            <status_change date="2011-10-17T13:06:24.384-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15629 - Found a few issues with the current inventory definition for VirtualBox and the vulnerability definition which uses it, and the fixes plus a bit more are attached. The core issue is that the registry key where the relevant information is stored has had 4 different values since version 3.0.0, with the most recent change causing the vulnerability definition to throw an error." date="2011-10-17T13:02:00.116-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-11-07T04:00:46.970-05:00">INTERIM</status_change>
            <status_change date="2011-11-28T04:00:19.930-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:12983 - modified vulnerabilities of Oracle Virtualbox (part 2)" date="2013-09-03T10:22:00.388-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-09-03T10:59:52.337-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:12025 - modified vulnerabilities of Oracle Virtualbox (part 3)" date="2013-09-03T10:59:00.280-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-09-23T04:00:07.009-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15297 - modificated vulnerabilities for VirtualBox" date="2013-12-05T10:43:00.197-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-05T10:45:12.286-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:00:14.881-05:00">ACCEPTED</status_change>
            <status_change date="2013-12-23T04:00:11.098-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:12983 - New vulnerability(CVE-2013-5892) added and modified existing criteria" date="2014-01-30T14:45:00.034-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-30T14:49:21.982-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:09.037-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="VirtualBox is installed" definition_ref="oval:org.mitre.oval:def:11581"/>
        <criteria operator="OR" comment="Affected versions of VirtualBox">
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Sun xVM VirtualBox is installed" test_ref="oval:org.mitre.oval:tst:41938"/>
            <criterion comment="Check if Sun xVM VirtualBox version is greater than or equals to 3.0.0" test_ref="oval:org.mitre.oval:tst:88496"/>
            <criterion comment="Check if Sun xVM VirtualBox version is less than or equals to 3.0.4" test_ref="oval:org.mitre.oval:tst:89093"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Sun VirtualBox is installed" test_ref="oval:org.mitre.oval:tst:44050"/>
            <criterion comment="Check if Sun VirtualBox version is greater than or equals to 3.0.6" test_ref="oval:org.mitre.oval:tst:88483"/>
            <criterion comment="Check if Sun VirtualBox version is less than or equals to 3.1.8" test_ref="oval:org.mitre.oval:tst:88393"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 3.2.0" test_ref="oval:org.mitre.oval:tst:88842"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than 4.1.0" test_ref="oval:org.mitre.oval:tst:100062"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1294" version="7" class="vulnerability">
      <metadata>
        <title>IFRAME Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1050" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1050"/>
        <description>Heap-based buffer overflow in Internet Explorer 6 allows remote attackers to execute arbitrary code via long (1) SRC or (2) NAME attributes in IFRAME, FRAME, and EMBED elements, as originally discovered using the mangleme utility, aka "the IFRAME vulnerability" or the "HTML Elements Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-05T05:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2005-01-12T05:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T05:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T05:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-02T04:00:00.000-04:00" comment="modified wrt-24 - corrected hotfix key">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-06-08T04:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-29T04:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="modified wrt-18 - Changed value element to include pattern match">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-07-03T12:56:00.000-04:00" comment="Added negate=true attribute to criteria sub-block to fix conversion error from OVAL 4.2 to OVAL 5.0">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-07-03T12:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:28:36.634-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:46:04.441-05:00">INTERIM</status_change>
            <modified comment="Added Microsoft Windows 2000 and Microsoft Windows XP to the affected platforms. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-22T20:00:00.869-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-02-20T13:39:38.746-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:36.570-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:13.078-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Internet Explorer 6.0 or IE 6.0 SP1 is installed">
          <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
        </criteria>
        <criteria operator="OR" comment="patch kb889293 is installed (hotfix or ID)" negate="true">
          <criterion comment="the patch kb889293 is installed (Installed Components key)" negate="false" test_ref="oval:org.mitre.oval:tst:1010"/>
          <criterion comment="the patch kb889293 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1009"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12915" version="3" class="vulnerability">
      <metadata>
        <title>Access of Unallocated Memory DoS Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Host Integration Server 2004</product>
          <product>Microsoft Host Integration Server 2006</product>
          <product>Microsoft Host Integration Server 2009</product>
          <product>Microsoft Host Integration Server 2010</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2011-2008" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2008"/>
        <description>Microsoft Host Integration Server (HIS) 2004 SP1, 2006 SP1, 2009, and 2010 allows remote attackers to cause a denial of service (SNA Server service outage) via crafted TCP or UDP traffic, aka "Access of Unallocated Memory DoS Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2011-10-11T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2011-10-17T09:26:40.632-04:00">DRAFT</status_change>
            <status_change date="2011-11-07T04:00:44.214-05:00">INTERIM</status_change>
            <status_change date="2011-11-28T04:00:16.447-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Microsoft Host Integration Server 2004 SP1">
          <extend_definition comment="Microsoft Host Integration Server 2004 SP1 is installed" definition_ref="oval:org.mitre.oval:def:5430"/>
          <criterion comment="Snadmod.dll version is less than 6.0.2445.0" test_ref="oval:org.mitre.oval:tst:43888"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Host Integration Server 2006">
          <extend_definition comment="Microsoft Host Integration Server 2006 is installed" definition_ref="oval:org.mitre.oval:def:5373"/>
          <criterion comment="Snadmod.dll version is less than 7.0.4220.0" test_ref="oval:org.mitre.oval:tst:44254"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Host Integration Server 2009">
          <extend_definition comment="Microsoft Host Integration Server 2009 is installed" definition_ref="oval:org.mitre.oval:def:12766"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Snadmod.dll version is less than 8.0.3850.1" test_ref="oval:org.mitre.oval:tst:44027"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Snadmod.dll version is less than 8.0.3872.2" test_ref="oval:org.mitre.oval:tst:43857"/>
              <criterion comment="Snadmod.dll version is greater than or equal to 8.0.3870.0" test_ref="oval:org.mitre.oval:tst:44243"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Microsoft Host Integration Server 2010">
          <extend_definition comment="Microsoft Host Integration Server 2010 is installed" definition_ref="oval:org.mitre.oval:def:12165"/>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Snadmod.dll version is less than 8.5.4317.1" test_ref="oval:org.mitre.oval:tst:44232"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Snadmod.dll version is less than 8.5.4369.2" test_ref="oval:org.mitre.oval:tst:44184"/>
              <criterion comment="Snadmod.dll version is greater than or equal to 8.5.4360.0" test_ref="oval:org.mitre.oval:tst:43281"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5430" version="6" class="inventory">
      <metadata>
        <title>Microsoft Host Integration Server 2004 SP1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Host Integration Server 2004</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:host_integration_server:2004:sp1"/>
        <description>A version of Microsoft Host Integration Server 2004 SP1 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2008-10-14T13:33:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-10-16T14:01:44.282-04:00">DRAFT</status_change>
            <modified comment="Corrected a misspelled title." date="2008-10-31T15:30:00.283-04:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </modified>
            <modified comment="Corrected a misspelled title." date="2008-10-31T15:30:00.180-04:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </modified>
            <modified comment="Corrected a misspelled title." date="2008-10-31T15:30:00.453-04:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2008-11-17T04:00:26.911-05:00">INTERIM</status_change>
            <status_change date="2008-12-08T04:00:51.015-05:00">ACCEPTED</status_change>
            <modified date="2009-06-15T04:44:54" comment="Added CPE">
              <contributor organization="The MITRE Corporation">Brendan Miles</contributor>
            </modified>
            <status_change date="2009-06-22T04:00:52.696-04:00">INTERIM</status_change>
            <status_change date="2009-07-13T04:00:37.030-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:6633 - Several updates including updated criterias, comments and CPE names." date="2011-10-21T10:01:00.242-04:00">
              <contributor organization="Secure Elements, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2011-10-21T10:10:01.691-04:00">INTERIM</status_change>
            <status_change date="2011-11-07T04:00:59.875-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:16103 - def:6075, Edited var:620 &amp; obj:6408 to use regex &amp; match different MS HIS version directories" date="2011-11-15T14:52:00.918-05:00">
              <contributor organization="SecPod Technologies">Pradeep R B</contributor>
            </modified>
            <status_change date="2011-11-15T14:53:31.906-05:00">INTERIM</status_change>
            <status_change date="2011-12-05T04:00:26.402-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Microsoft Host Integration Server 2004 is installed" test_ref="oval:org.mitre.oval:tst:8356"/>
        <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Host Integration Server\6.0!ProductVersion = 6.0.2403.0" test_ref="oval:org.mitre.oval:tst:44390"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5373" version="4" class="inventory">
      <metadata>
        <title>Microsoft Host Integration Server 2006 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Host Integration Server 2006</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:host_integration_server:2006"/>
        <description>A version of Microsoft Host Integration Server 2006 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2008-10-14T13:33:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-10-16T14:01:43.227-04:00">DRAFT</status_change>
            <modified comment="Corrected a misspelled title." date="2008-10-31T15:30:00.045-04:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </modified>
            <modified comment="Corrected a misspelled title." date="2008-10-31T15:30:00.198-04:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2008-11-17T04:00:26.562-05:00">INTERIM</status_change>
            <status_change date="2008-12-08T04:00:50.571-05:00">ACCEPTED</status_change>
            <modified date="2009-06-15T04:44:54" comment="Added CPE">
              <contributor organization="The MITRE Corporation">Brendan Miles</contributor>
            </modified>
            <status_change date="2009-06-22T04:00:52.167-04:00">INTERIM</status_change>
            <status_change date="2009-07-13T04:00:35.416-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5373 - Updated CPE name" date="2011-10-21T10:13:00.283-04:00">
              <contributor organization="Secure Elements, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2011-10-21T10:27:10.002-04:00">INTERIM</status_change>
            <status_change date="2011-11-07T04:00:59.515-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Microsoft Host Integration Server 2006 is installed" test_ref="oval:org.mitre.oval:tst:9310"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12766" version="4" class="inventory">
      <metadata>
        <title>Microsoft Host Integration Server 2009 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Host Integration Server 2009</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:host_integration_server:2009"/>
        <description>A version of Microsoft Host Integration Server 2009 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2011-10-11T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2011-10-17T09:26:39.882-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:12766 - Updated CPE name" date="2011-10-21T10:13:00.283-04:00">
              <contributor organization="Secure Elements, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2011-11-07T04:00:40.794-05:00">INTERIM</status_change>
            <status_change date="2011-11-28T04:00:11.269-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Microsoft Host Integration Server 2009 is installed" test_ref="oval:org.mitre.oval:tst:44117"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12165" version="4" class="inventory">
      <metadata>
        <title>Microsoft Host Integration Server 2010 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Host Integration Server 2010</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:host_integration_server:2010"/>
        <description>A version of Microsoft Host Integration Server 2010 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2011-10-11T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2011-10-17T09:26:40.129-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:12165 - Updated CPE name" date="2011-10-21T10:13:00.283-04:00">
              <contributor organization="Secure Elements, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2011-11-07T04:00:32.862-05:00">INTERIM</status_change>
            <status_change date="2011-11-28T04:00:04.165-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Microsoft Host Integration Server 2010 is installed" test_ref="oval:org.mitre.oval:tst:43549"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1291" version="6" class="vulnerability">
      <metadata>
        <title>Windows Explorer Web View Script Injection Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2117" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2117"/>
        <description>Web View in Windows Explorer on Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 does not properly handle certain HTML characters in preview fields, which allows remote user-assisted attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-31T12:00:00.000-04:00" comment="removed an incorrect leading ^ from the value entity of ste:2402">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-31T00:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:16.554-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1291 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:06:43.804-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:00:47.926-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Windows 2000 is installed" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="Win2K/XP/2003 service pack 4 is installed" test_ref="oval:org.mitre.oval:tst:2569"/>
        <criterion comment="shell32.dll is less than 5.0.3900.7071" test_ref="oval:org.mitre.oval:tst:1086"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1290" version="9" class="vulnerability">
      <metadata>
        <title>IE6 HTML Tag Memory Corruption (Win2K/WinXP)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1188" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1188"/>
        <description>Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via HTML elements with a certain crafted tag, which leads to memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added an anchor to the regex used to check for Internet Explorer 6." date="2007-01-11T20:38:00.950-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-01-11T20:49:15.274-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:38.549-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:2185 - Anchored regular expression" date="2011-02-22T12:51:00.261-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:52:29.852-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:00:46.147-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:43:53.834-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:00:47.519-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:36.310-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:12.850-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Win2K or XP,SP1 is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="Internet Explorer 6 (any patch level) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2333"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2800.1543" negate="false" test_ref="oval:org.mitre.oval:tst:2332"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1289" version="6" class="vulnerability">
      <metadata>
        <title>Network Connection Manager Interruption of Service (Windows 2000)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2307" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2307"/>
        <description>netman.dll in Microsoft Windows Connections Manager Library allows local users to cause a denial of service (Network Connections Service crash) via a large integer argument to a particular function, aka "Network Connection Manager Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-31T12:00:00.000-04:00" comment="removed an incorrect leading ^ from the value entity of ste:2402">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-31T00:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:16.291-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1289 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:05:45.310-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:00:47.211-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Windows 2000 is installed" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="Win2K/XP/2003 service pack 4 is installed" test_ref="oval:org.mitre.oval:tst:2569"/>
        <criterion comment="netman.dll is less than 5.0.2195.7061" test_ref="oval:org.mitre.oval:tst:1011"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1288" version="5" class="vulnerability">
      <metadata>
        <title>Win2k Land Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0688" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0688"/>
        <description>Windows Server 2003 and XP SP2, with Windows Firewall turned off, allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet with the SYN flag set and the same destination and source address and port, aka a reoccurrence of the "Land" vulnerability (CVE-1999-0016).</description>
        <oval_repository>
          <dates>
            <submitted date="2005-04-22T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-04-27T12:06:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-11-06T04:13:00.000-04:00" comment="Replaced reference to var:200 with reference to var:201 in obj:588 since tcpip.sys is located in \system32\drivers and not \system32.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:53:49.217-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:43:59.317-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:00:46.822-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="Win2K/XP/2003 service pack 4 (or earlier) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1247"/>
        <criterion comment="the version of Tcpip.sys is less than 5.0.2195.7035" negate="false" test_ref="oval:org.mitre.oval:tst:1012"/>
        <criterion comment="the patch KB893066 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2353"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12864" version="5" class="vulnerability">
      <metadata>
        <title>Contact Details Reflected XSS Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Windows SharePoint Services 3.0</product>
          <product>Microsoft SharePoint Foundation 2010</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2011-1891" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1891"/>
        <description>Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters in a request to a script, aka "Contact Details Reflected XSS Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-13T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2011-09-20T09:24:29.926-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:33.744-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:58.408-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:12311 - MS13-084, 085 and 067 bulletins" date="2013-10-23T11:46:00.610-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2013-10-23T11:49:37.786-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:00:06.785-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Vulnerable Microsoft Windows SharePoint Services 3.0">
          <criterion comment="Microsoft Windows SharePoint Services 3.0 are installed" test_ref="oval:org.mitre.oval:tst:27622"/>
          <criterion comment="the version of Onetutil.dll is less than 12.0.6565.5001" test_ref="oval:org.mitre.oval:tst:42957"/>
        </criteria>
        <criteria comment="Vulnerable Microsoft SharePoint Foundation 2010">
          <extend_definition comment="Microsoft SharePoint Foundation 2010 is installed" definition_ref="oval:org.mitre.oval:def:12224"/>
          <criterion comment="OWSSVR.DLL version is less than 14.0.6106.5008" test_ref="oval:org.mitre.oval:tst:43889"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12835" version="3" class="vulnerability">
      <metadata>
        <title>XSS in SharePoint Calendar Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft SharePoint Server 2010</product>
          <product>Microsoft SharePoint Foundation 2010</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2011-0653" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0653"/>
        <description>Cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint Server 2010 Gold and SP1, and SharePoint Foundation 2010, allows remote attackers to inject arbitrary web script or HTML via the URI, aka "XSS in SharePoint Calendar Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-13T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2011-09-20T09:24:27.187-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:30.316-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:53.708-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Vulnerable Microsoft Office SharePoint Server 2010 (osrchwfe)">
          <extend_definition comment="Microsoft Office SharePoint Server 2010 is installed." definition_ref="oval:org.mitre.oval:def:12880"/>
          <criterion comment="Microsoft.SharePoint.Taxonomy.dll version is less than 14.0.6106.5001" test_ref="oval:org.mitre.oval:tst:43686"/>
        </criteria>
        <criteria comment="Vulnerable Microsoft Office SharePoint Server 2010 (osrv/wosrv)">
          <extend_definition comment="Microsoft Office SharePoint Server 2010 is installed." definition_ref="oval:org.mitre.oval:def:12880"/>
          <criterion comment="Microsoft.office.server.dll version is less than 14.0.6106.5001" test_ref="oval:org.mitre.oval:tst:43358"/>
        </criteria>
        <criteria comment="Vulnerable Microsoft Office SharePoint Server 2010 (ppsmawfe)">
          <extend_definition comment="Microsoft Office SharePoint Server 2010 is installed." definition_ref="oval:org.mitre.oval:def:12880"/>
          <criterion comment="Eawfap.dll version is less than 14.0.6106.5001" test_ref="oval:org.mitre.oval:tst:43900"/>
        </criteria>
        <criteria comment="Vulnerable Microsoft Office SharePoint Server 2010 (dlc)">
          <extend_definition comment="Microsoft Office SharePoint Server 2010 is installed." definition_ref="oval:org.mitre.oval:def:12880"/>
          <criterion comment="Microsoft.office.policy.dll version is less than 14.0.6106.5001" test_ref="oval:org.mitre.oval:tst:43892"/>
        </criteria>
        <criteria comment="Vulnerable Microsoft Office SharePoint Server 2010 (ppsmamui)">
          <extend_definition comment="Microsoft Office SharePoint Server 2010 is installed." definition_ref="oval:org.mitre.oval:def:12880"/>
          <criterion comment="Microsoft.SharePoint.Client.dll version is less than 14.0.6106.5001" test_ref="oval:org.mitre.oval:tst:43419"/>
        </criteria>
        <criteria comment="Vulnerable Microsoft SharePoint Foundation 2010">
          <extend_definition comment="Microsoft SharePoint Foundation 2010 is installed" definition_ref="oval:org.mitre.oval:def:12224"/>
          <criterion comment="OWSSVR.DLL version is less than 14.0.6106.5008" test_ref="oval:org.mitre.oval:tst:43889"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12829" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft Internet Explorer 'AddFavorite' Method Denial of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2433" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2433"/>
        <description>Stack-based buffer overflow in the AddFavorite method in Microsoft Internet Explorer allows remote attackers to cause a denial of service (application crash) and possibly have unspecified other impact via a long URL in the first argument.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-06-28T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2011-07-05T22:14:56.520-04:00">DRAFT</status_change>
            <status_change date="2011-07-25T04:00:10.289-04:00">INTERIM</status_change>
            <status_change date="2011-08-15T04:00:09.528-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
        <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12817" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft Internet Explorer 6 through 8 spoofing vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3003" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3003"/>
        <description>Microsoft Internet Explorer 6 through 8 allows remote attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary URL on the web site visited by the victim, as demonstrated by a visit to an attacker-controlled web page, which triggers a spoofed login form for the site containing that page.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-06-28T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2011-07-05T22:14:57.504-04:00">DRAFT</status_change>
            <status_change date="2011-07-25T04:00:09.907-04:00">INTERIM</status_change>
            <status_change date="2011-08-15T04:00:09.212-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
        <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
        <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1280" version="6" class="vulnerability">
      <metadata>
        <title>Windows 2000 Color Management Module Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Color Management Module</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1219" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1219"/>
        <description>Buffer overflow in the Microsoft Color Management Module for Windows allows remote attackers to execute arbitrary code via an image with crafted ICC profile format tags.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-02T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-08-03T11:30:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected and tightened regular expression in ste:2610" date="2010-12-02T11:46:00.307-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-12-02T11:47:27.708-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:31.613-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:43:59.841-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:00:46.156-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 (sp4 or earlier) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 5 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2790"/>
        </criteria>
        <criterion comment="the version of mscms.dll is less than 5.0.2195.7054" negate="false" test_ref="oval:org.mitre.oval:tst:1017"/>
        <criterion comment="the patch KB901214 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2697"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12788" version="3" class="vulnerability">
      <metadata>
        <title>Editform Script Injection Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft SharePoint Server 2010</product>
          <product>Microsoft SharePoint Foundation 2010</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2011-1890" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1890"/>
        <description>Cross-site scripting (XSS) vulnerability in EditForm.aspx in Microsoft Office SharePoint Server 2010 and SharePoint Foundation 2010 allows remote attackers to inject arbitrary web script or HTML via a post, aka "Editform Script Injection Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-13T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2011-09-20T09:24:29.615-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:26.156-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:48.722-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Vulnerable Microsoft Office SharePoint Server 2010 (osrchwfe)">
          <extend_definition comment="Microsoft Office SharePoint Server 2010 is installed." definition_ref="oval:org.mitre.oval:def:12880"/>
          <criterion comment="Microsoft.SharePoint.Taxonomy.dll version is less than 14.0.6106.5001" test_ref="oval:org.mitre.oval:tst:43686"/>
        </criteria>
        <criteria comment="Vulnerable Microsoft Office SharePoint Server 2010 (osrv/wosrv)">
          <extend_definition comment="Microsoft Office SharePoint Server 2010 is installed." definition_ref="oval:org.mitre.oval:def:12880"/>
          <criterion comment="Microsoft.office.server.dll version is less than 14.0.6106.5001" test_ref="oval:org.mitre.oval:tst:43358"/>
        </criteria>
        <criteria comment="Vulnerable Microsoft Office SharePoint Server 2010 (ppsmawfe)">
          <extend_definition comment="Microsoft Office SharePoint Server 2010 is installed." definition_ref="oval:org.mitre.oval:def:12880"/>
          <criterion comment="Eawfap.dll version is less than 14.0.6106.5001" test_ref="oval:org.mitre.oval:tst:43900"/>
        </criteria>
        <criteria comment="Vulnerable Microsoft Office SharePoint Server 2010 (dlc)">
          <extend_definition comment="Microsoft Office SharePoint Server 2010 is installed." definition_ref="oval:org.mitre.oval:def:12880"/>
          <criterion comment="Microsoft.office.policy.dll version is less than 14.0.6106.5001" test_ref="oval:org.mitre.oval:tst:43892"/>
        </criteria>
        <criteria comment="Vulnerable Microsoft Office SharePoint Server 2010 (ppsmamui)">
          <extend_definition comment="Microsoft Office SharePoint Server 2010 is installed." definition_ref="oval:org.mitre.oval:def:12880"/>
          <criterion comment="Microsoft.SharePoint.Client.dll version is less than 14.0.6106.5001" test_ref="oval:org.mitre.oval:tst:43419"/>
        </criteria>
        <criteria comment="Vulnerable Microsoft SharePoint Foundation 2010">
          <extend_definition comment="Microsoft SharePoint Foundation 2010 is installed" definition_ref="oval:org.mitre.oval:def:12224"/>
          <criterion comment="OWSSVR.DLL version is less than 14.0.6106.5008" test_ref="oval:org.mitre.oval:tst:43889"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12880" version="5" class="inventory">
      <metadata>
        <title>Microsoft Office SharePoint Server 2010 is installed.</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Office SharePoint Server 2010</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:sharepoint:2010"/>
        <description>Microsoft Office SharePoint Server 2010 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-13T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2011-09-20T09:24:26.061-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:35.882-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:01:00.596-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:16204 - New Microsoft Patch Tuesday October 2012 definitions." date="2012-10-19T16:09:00.822-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-10-19T16:30:25.998-04:00">INTERIM</status_change>
            <status_change date="2012-11-05T04:00:03.694-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="SharePoint Server 2010 is installed." test_ref="oval:org.mitre.oval:tst:43555"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12224" version="5" class="inventory">
      <metadata>
        <title>Microsoft SharePoint Foundation 2010 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8</platform>
          <product>Microsoft SharePoint Foundation 2010</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:sharepoint_foundation:2010"/>
        <description>Microsoft SharePoint Foundation 2010 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-13T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2011-09-20T09:24:26.985-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:07.602-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:15.672-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:12224 - Microsoft Bulletins: MS13-024 and MS13-025 (March 2013)" date="2013-03-18T14:50:00.119-04:00">
              <contributor organization="SecPod Technologies">Bhavya K</contributor>
            </modified>
            <status_change date="2013-03-18T14:53:11.905-04:00">INTERIM</status_change>
            <status_change date="2013-04-08T04:00:07.906-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="SharePoint Foundation 2010 is installed." test_ref="oval:org.mitre.oval:tst:43939"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1275" class="vulnerability" version="1">
      <metadata>
        <title>Windows Services for UNIX Could Allow Elevation of Privilege</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3036" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3036"/>
        <description>Unspecified vulnerability in the (1) Windows Services for UNIX 3.0 and 3.5, and (2) Subsystem for UNIX-based Applications in Microsoft Windows 2000, XP, Server 2003, and Vista allows local users to gain privileges via unspecified vectors related to "certain setuid binary files."</description>
        <oval_repository>
          <dates>
            <submitted date="2007-09-13T11:40:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <modified date="2007-09-14T11:19:00" comment="Added tests to check to see what the version of psxss.exe starts with.">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2007-09-12T15:03:46.100-04:00">DRAFT</status_change>
            <status_change date="2007-10-02T08:08:08.256-04:00">INTERIM</status_change>
            <status_change date="2007-10-18T21:59:19.396-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="POSIX is enabled" test_ref="oval:org.mitre.oval:tst:609"/>
        <criteria operator="OR">
          <criteria operator="AND" comment="UNIX 3.0 version on Windows 2000 SP4, Windows XP SP2, Windows Server 2003 SP1 and Windows Server 2003 SP2">
            <criteria operator="OR" comment="Windows 2000 SP4, Windows XP SP2, Windows Server 2003 SP1 and Windows Server 2003 SP2">
              <extend_definition comment="Microsoft Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
              <extend_definition comment="Microsoft Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
              <extend_definition comment="Microsoft Windows Server 2003 (x86) SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
              <extend_definition comment="Microsoft Windows Server 2003 (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            </criteria>
            <criterion comment="the version of psxss.exe is less than 7.0.1701.46" test_ref="oval:org.mitre.oval:tst:3240"/>
            <criteria operator="AND" comment="The major version of Psxss.exe 7.">
              <criterion comment="the version of psxss.exe is greater than or equal to 7." test_ref="oval:org.mitre.oval:tst:3242"/>
              <criterion comment="The version of Psxss.exe is less than 8." test_ref="oval:org.mitre.oval:tst:3405"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="UNIX 3.5 version on Windows 2000 SP4, Windows XP SP2, Windows Server 2003 SP1 and Windows Server 2003 SP2">
            <criteria operator="OR" comment="Windows 2000 SP4, Windows XP SP2, Windows Server 2003 SP1 and Windows Server 2003 SP2">
              <extend_definition comment="Microsoft Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
              <extend_definition comment="Microsoft Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
              <extend_definition comment="Microsoft Windows Server 2003 (x86) SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
              <extend_definition comment="Microsoft Windows Server 2003 (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            </criteria>
            <criterion comment="the version of psxss.exe is less than 8.0.1969.58" test_ref="oval:org.mitre.oval:tst:4052"/>
            <criterion comment="the version of psxss.exe starts with 8" test_ref="oval:org.mitre.oval:tst:3247"/>
            <criteria operator="AND" comment="The major version of Psxss.exe 8.">
              <criterion comment="the version of psxss.exe is greater than or equal to 8." test_ref="oval:org.mitre.oval:tst:3247"/>
              <criterion comment="The version of Psxss.exe is less than 9." test_ref="oval:org.mitre.oval:tst:3845"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Windows Server 2003 SP1">
            <extend_definition comment="Microsoft Windows Server 2003 (x86) SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <criterion comment="the version of psxss.exe is less than 9.0.3790.2983" test_ref="oval:org.mitre.oval:tst:3905"/>
            <criteria operator="AND" comment="The major version of Psxss.exe 9.">
              <criterion comment="the version of psxss.exe is greater than or equal to 9." test_ref="oval:org.mitre.oval:tst:4118"/>
              <criterion comment="The version of Psxss.exe is less than 10." test_ref="oval:org.mitre.oval:tst:4243"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Windows Server 2003 SP2">
            <extend_definition comment="Microsoft Windows Server 2003 (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <criterion comment="the version of psxss.exe is less than 9.0.3790.4125" test_ref="oval:org.mitre.oval:tst:3464"/>
            <criteria operator="AND" comment="The major version of Psxss.exe 9.">
              <criterion comment="the version of psxss.exe is greater than or equal to 9." test_ref="oval:org.mitre.oval:tst:4118"/>
              <criterion comment="The version of Psxss.exe is less than 10." test_ref="oval:org.mitre.oval:tst:4243"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Windows Server 2003 SP1 (x64)">
            <extend_definition comment="Microsoft Windows Server 2003 (x64) SP1 is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <criterion comment="the version of psxss.exe is less than 9.0.3790.2983" test_ref="oval:org.mitre.oval:tst:3905"/>
            <criteria operator="AND" comment="The major version of Psxss.exe 9.">
              <criterion comment="the version of psxss.exe is greater than or equal to 9." test_ref="oval:org.mitre.oval:tst:4118"/>
              <criterion comment="The version of Psxss.exe is less than 10." test_ref="oval:org.mitre.oval:tst:4243"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Windows Server 2003 SP2 (x64)">
            <extend_definition comment="Microsoft Windows Server 2003 (x64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <criterion comment="the version of psxss.exe is less than 9.0.3790.4125" test_ref="oval:org.mitre.oval:tst:3464"/>
            <criteria operator="AND" comment="The major version of Psxss.exe 9.">
              <criterion comment="the version of psxss.exe is greater than or equal to 9." test_ref="oval:org.mitre.oval:tst:4118"/>
              <criterion comment="The version of Psxss.exe is less than 10." test_ref="oval:org.mitre.oval:tst:4243"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Windows Vista">
            <extend_definition comment="Microsoft Windows Vista (x86) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <criterion comment="the version of psxss.exe is less than 6.0.6000.20660" test_ref="oval:org.mitre.oval:tst:3785"/>
            <criteria operator="AND" comment="The major version of Psxss.exe 6.">
              <criterion comment="the version of psxss.exe is greater than or equal to 6." test_ref="oval:org.mitre.oval:tst:3251"/>
              <criterion comment="The version of Psxss.exe is less than 7." test_ref="oval:org.mitre.oval:tst:4252"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1272" version="3" class="vulnerability">
      <metadata>
        <title>Object Spoofing using XBL &lt;implements> Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2704" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2704"/>
        <description>Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to spoof DOM objects via an XBL control that implements an internal XPCOM interface.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-11T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-12T10:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:2367" date="2007-02-26T08:32:00.241-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-26T08:32:37.808-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:2370" date="2007-03-06T07:46:00.064-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:47.362-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:1444" date="2007-04-23T12:05:00.911-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:19:58.010-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:1445" date="2007-04-23T12:05:00.720-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:10:52.971-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Suite version 1.7.10 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.10 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2535"/>
          <criterion comment="Mozilla Suite version 1.7.10 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2534"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.6 or earlier is installed">
          <criterion comment="Firefox version 1.0.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2533"/>
          <criterion comment="Mozilla Firefox version 1.0.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2532"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12701" version="3" class="vulnerability">
      <metadata>
        <title>Security bypass vulnerability in Apache Tomcat 7.0.11</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Apache Tomcat</product>
        </affected>
        <reference ref_id="CVE-2011-1183" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1183" source="CVE"/>
        <description>Apache Tomcat 7.0.11, when web.xml has no login configuration, does not follow security constraints, which allows remote attackers to bypass intended access restrictions via HTTP requests to a meta-data complete web application.  NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-1088 and CVE-2011-1419.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-05-04T09:29:28-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-05-06T15:23:46.860-04:00">DRAFT</status_change>
            <status_change date="2011-05-23T04:00:17.269-04:00">INTERIM</status_change>
            <status_change date="2011-06-13T04:00:13.294-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Apache Tomcat is installed" definition_ref="oval:org.mitre.oval:def:12401"/>
        <criterion comment="Check if Apache Tomcat version is equal to 7.0.11" test_ref="oval:org.mitre.oval:tst:42572"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:127" version="6" class="vulnerability">
      <metadata>
        <title>RPCSS DCOM Buffer Overflow (Windows 2000)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Remote Procedure Call (RPC)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0528" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0528"/>
        <description>Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed RPC request with a long filename parameter, a different vulnerability than CVE-2003-0352 (Blaster/Nachi) and CVE-2003-0715.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-15T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Multiple corrections and update to POSIX compatibility for ste:2884" date="2010-11-29T16:14:00.692-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-11-29T16:14:38.619-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:31.348-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:37.108-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:00:45.782-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="the version of rpcrt4.dll is less than 5.0.2195.6802" negate="false" test_ref="oval:org.mitre.oval:tst:2914"/>
          <criterion comment="the patch kb824146 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:3082"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="DCOM is enabled on systems with SP3 or later">
            <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3079"/>
            <criterion comment="DCOM is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2913"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1267" version="8" class="vulnerability">
      <metadata>
        <title>Win2k,SP4 DirectShow Malicious avi File Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>DirectX</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2128" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2128"/>
        <description>QUARTZ.DLL in Microsoft Windows Media Player 9 allows remote attackers to write a null byte to arbitrary memory via an AVI file with a crafted strn element with a modified length value.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Multiple corrections and update to POSIX compatibility for ste:2878" date="2010-11-29T16:13:00.904-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-11-29T16:14:05.186-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:30.953-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:46:24.005-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:00:45.104-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:1047 - obj/ste updates to conform to authoring style guide" date="2013-03-26T09:53:00.500-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-03-26T09:56:05.377-04:00">INTERIM</status_change>
            <status_change date="2013-04-15T04:00:09.433-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="DirectX packaged with Windows 2000,SP4 has DirectShow Vulnerability">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="SP4 or later Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3073"/>
          <criterion comment="the version of Quartz.dll is greater than or equal to 6.1.9.726" negate="false" test_ref="oval:org.mitre.oval:tst:1027"/>
          <criterion comment="the version of Quartz.dll is less than 6.1.9.732" negate="false" test_ref="oval:org.mitre.oval:tst:1026"/>
        </criteria>
        <criteria operator="AND" comment="Standalone DirectX 8 has DirectShow Vulnerability">
          <criterion comment="DirectX 8.x Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1173"/>
          <criterion comment="the version of Quartz.dll is less than 6.3.1.889" negate="false" test_ref="oval:org.mitre.oval:tst:1121"/>
        </criteria>
        <criteria operator="AND" comment="Standalone DirectX 9 has DirectShow Vulnerability">
          <criterion comment="DirectX 9.x Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1120"/>
          <criterion comment="the version of Quartz.dll is less than 6.3.1.889" negate="false" test_ref="oval:org.mitre.oval:tst:1121"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1266" version="2" class="vulnerability">
      <metadata>
        <title>Mozilla Crashes with Evidence of Memory Corruption (Firefox Regression Fix)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1790" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1790"/>
        <description>A regression fix in Mozilla Firefox 1.0.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the InstallTrigger.install method, which leads to memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-07T09:05:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:16.094-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:917" date="2007-03-06T08:02:00.303-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-06T08:03:16.386-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:16:47.157-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.7 is installed">
          <criterion comment="Mozilla Firefox version 1.0.7 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1029"/>
          <criterion comment="Firefox version 1.0.7 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1028"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12638" version="4" class="vulnerability">
      <metadata>
        <title>Microsoft Internet Explorer cross-site scripting (XSS) vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1489" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1489"/>
        <description>The XSS Filter in Microsoft Internet Explorer 8 does not properly perform neutering for the SCRIPT tag, which allows remote attackers to conduct cross-site scripting (XSS) attacks against web sites that have no inherent XSS vulnerabilities, a different issue than CVE-2009-4074.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-06-28T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2011-07-05T22:14:57.974-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:12638 - Fixed typo in title." date="2011-07-22T14:49:00.513-04:00">
              <contributor organization="Digital Defense, Inc.">Brandon Shilling</contributor>
            </modified>
            <status_change date="2011-08-08T04:00:27.166-04:00">INTERIM</status_change>
            <status_change date="2011-08-29T04:00:06.577-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12620" version="3" class="vulnerability">
      <metadata>
        <title>SQL Injection vulnerability in PHP 5.3.2 and 5.3.3, when the MySQLi extension is used.</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>PHP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-4700" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4700"/>
        <description>The set_magic_quotes_runtime function in PHP 5.3.2 and 5.3.3, when the MySQLi extension is used, does not properly interact with use of the mysqli_fetch_assoc function, which might make it easier for context-dependent attackers to conduct SQL injection attacks via crafted input that had been properly handled in earlier PHP versions.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-03-22T15:12:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-03-22T13:47:56.314-04:00">DRAFT</status_change>
            <status_change date="2011-04-11T04:00:13.337-04:00">INTERIM</status_change>
            <status_change date="2011-05-02T04:00:09.234-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="PHP is installed" definition_ref="oval:org.mitre.oval:def:12410"/>
        <criterion comment="Check if the version of PHP is equal to 5.3.2 or equal to 5.3.3" test_ref="oval:org.mitre.oval:tst:42438"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:126" version="3" class="vulnerability">
      <metadata>
        <title>IE v6.0 Improper Cross Domain Security Validation with Dialog Box</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1326" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1326"/>
        <description>Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model to run malicious script or arbitrary programs via dialog boxes, aka "Improper Cross Domain Security Validation with dialog box."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-27T05:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Changed IE registry test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:43.064-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:11.754-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the version of mshtml.dll is less than 6.0.2723.2500" negate="false" test_ref="oval:org.mitre.oval:tst:3003"/>
        <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12589" version="4" class="vulnerability">
      <metadata>
        <title>Integer overflow vulnerability in the mt_rand function in PHP before 5.3.4</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>PHP</product>
        </affected>
        <reference ref_id="CVE-2011-0755" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0755" source="CVE"/>
        <description>Integer overflow in the mt_rand function in PHP before 5.3.4 might make it easier for context-dependent attackers to predict the return values by leveraging a script's use of a large max parameter, as demonstrated by a value that exceeds mt_getrandmax.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-03-29T09:34:18-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-03-29T14:26:02.162-04:00">DRAFT</status_change>
            <status_change date="2011-04-18T04:00:29.392-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:12589 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-09T04:00:59.972-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="PHP is installed" definition_ref="oval:org.mitre.oval:def:12410"/>
        <criterion comment="Check if the version of PHP is less than 5.3.4" test_ref="oval:org.mitre.oval:tst:41865"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12576" version="10" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in Oracle VM VirtualBox 4.0</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Oracle VM VirtualBox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-4414" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4414"/>
        <description>Unspecified vulnerability in Oracle VM VirtualBox 4.0 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Extensions.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-03-16T16:16:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-03-18T16:57:25.382-04:00">DRAFT</status_change>
            <status_change date="2011-04-04T04:00:22.590-04:00">INTERIM</status_change>
            <status_change date="2011-04-25T04:00:17.396-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:42349 - Found a few issues with the current inventory definition for VirtualBox and the vulnerability definition which uses it, and the fixes plus a bit more are attached. The core issue is that the registry key where the relevant information is stored has had 4 different values since version 3.0.0, with the most recent change causing the vulnerability definition to throw an error." date="2011-10-17T13:02:00.116-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-10-17T13:24:14.993-04:00">INTERIM</status_change>
            <status_change date="2011-11-07T04:00:37.998-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:12025 - modified vulnerabilities of Oracle Virtualbox (part 3)" date="2013-09-03T10:59:00.280-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-09-03T11:01:14.619-04:00">INTERIM</status_change>
            <status_change date="2013-09-23T04:00:06.496-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15297 - modificated vulnerabilities for VirtualBox" date="2013-12-05T10:43:00.197-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-05T10:45:12.217-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:00:14.534-05:00">ACCEPTED</status_change>
            <status_change date="2013-12-23T04:00:10.810-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="VirtualBox is installed" definition_ref="oval:org.mitre.oval:def:11581"/>
        <criterion comment="Check if Oracle VM VirtualBox is installed" test_ref="oval:org.mitre.oval:tst:42006"/>
        <criterion comment="Check if Oracle VM VirtualBox version equal to 4.0.0" test_ref="oval:org.mitre.oval:tst:88790"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11581" version="9" class="inventory">
      <metadata>
        <title>VirtualBox is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>VirtualBox</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:oracle:xvm_virtualbox"/>
        <description>VirtualBox is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2010-12-17T19:26:32">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-12-21T11:27:26.795-05:00">DRAFT</status_change>
            <status_change date="2011-01-10T04:00:04.930-05:00">INTERIM</status_change>
            <status_change date="2011-01-31T04:00:03.574-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11581 - Modified inventory definition CPE IDs to match the CPE IDs found in the official CPE dictionary" date="2011-03-29T13:53:00.154-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-03-29T13:54:37.133-04:00">INTERIM</status_change>
            <status_change date="2011-04-18T04:00:03.500-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11581 - Found a few issues with the current inventory definition for VirtualBox and the vulnerability definition which uses it, and the fixes plus a bit more are attached. The core issue is that the registry key where the relevant information is stored has had 4 different values since version 3.0.0, with the most recent change causing the vulnerability definition to throw an error." date="2011-10-17T13:02:00.116-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-10-17T13:24:26.817-04:00">INTERIM</status_change>
            <status_change date="2011-11-07T04:00:09.278-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15297 - modificated vulnerabilities for VirtualBox" date="2013-12-05T10:43:00.197-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-05T10:45:12.057-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:00:06.821-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Check if Sun xVM VirtualBox is installed" test_ref="oval:org.mitre.oval:tst:41938"/>
        <criterion comment="Check if Sun VirtualBox is installed" test_ref="oval:org.mitre.oval:tst:44050"/>
        <criterion comment="Check if Oracle VM VirtualBox is installed" test_ref="oval:org.mitre.oval:tst:42006"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12569" version="3" class="vulnerability">
      <metadata>
        <title>NULL byte injection vulnerability in PHP before 5.3.4</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>PHP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-7243" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-7243"/>
        <description>PHP before 5.3.4 accepts the \0 character in a pathname, which might allow context-dependent attackers to bypass intended access restrictions by placing a safe file extension after this character, as demonstrated by .php\0.jpg at the end of the argument to the file_exists function.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-03-22T16:21:49">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-03-22T13:47:57.444-04:00">DRAFT</status_change>
            <status_change date="2011-04-11T04:00:12.473-04:00">INTERIM</status_change>
            <status_change date="2011-05-02T04:00:08.860-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="PHP is installed" definition_ref="oval:org.mitre.oval:def:12410"/>
        <criterion comment="Check if the version of PHP is less than 5.3.4" test_ref="oval:org.mitre.oval:tst:42273"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1253" version="4" class="vulnerability">
      <metadata>
        <title>Distributed TIP Request Validation Process Permits Denial of Service (Win2k,SP4)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>TIP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1980" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1980"/>
        <description>Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service hang) via a crafted Transaction Internet Protocol (TIP) message that causes DTC to repeatedly connect to a target IP and port number after an error occurs, aka the "Distributed TIP Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:46:48.575-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:00:41.434-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="Win2K/XP/2003 service pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2569"/>
        <criteria operator="OR" comment="Either ole32.dll or rpcss.dll has a version less than 5.0.2195.7059">
          <criterion comment="the version of ole32.dll is less than 5.0.2195.7059" negate="false" test_ref="oval:org.mitre.oval:tst:2568"/>
          <criterion comment="the version of rpcss.dll is less than 5.0.2195.7059" negate="false" test_ref="oval:org.mitre.oval:tst:2567"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12528" version="3" class="vulnerability">
      <metadata>
        <title>Use-after-free vulnerability in the Zend engine in PHP before 5.2.15 and 5.3.x before 5.3.4</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>PHP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-4697" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4697"/>
        <description>Use-after-free vulnerability in the Zend engine in PHP before 5.2.15 and 5.3.x before 5.3.4 might allow context-dependent attackers to cause a denial of service (heap memory corruption) or have unspecified other impact via vectors related to use of __set, __get, __isset, and __unset methods on objects accessed by a reference.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-03-22T16:21:49">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-03-22T13:47:57.132-04:00">DRAFT</status_change>
            <status_change date="2011-04-11T04:00:10.780-04:00">INTERIM</status_change>
            <status_change date="2011-05-02T04:00:08.188-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="PHP is installed" definition_ref="oval:org.mitre.oval:def:12410"/>
        <criterion comment="Check if the version of PHP is less than 5.2.15 or 5.3.x before 5.3.4" test_ref="oval:org.mitre.oval:tst:42457"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12501" version="3" class="vulnerability">
      <metadata>
        <title>Buffer overrun in Chunked Encoding mechanism</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows NT</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0079" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0079"/>
        <description>Buffer overflow in the chunked encoding transfer mechanism in Internet Information Server (IIS) 4.0 and 5.0 Active Server Pages allows attackers to cause a denial of service or execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-16T12:00:00.000-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2011-01-12T13:28:44.626-05:00">DRAFT</status_change>
            <status_change date="2011-01-31T04:00:13.229-05:00">INTERIM</status_change>
            <status_change date="2011-02-21T04:00:38.728-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="vulnerable IIS 4.0 on Windows NT">
          <extend_definition comment="Microsoft Windows NT is installed" definition_ref="oval:org.mitre.oval:def:36"/>
          <extend_definition comment="Microsoft IIS 4.0 is installed" definition_ref="oval:org.mitre.oval:def:12482"/>
          <criterion comment="the version of w3svc.dll is less than 4.2.775.1" test_ref="oval:org.mitre.oval:tst:42232"/>
          <criterion comment="FTP Enabled" test_ref="oval:org.mitre.oval:tst:3074"/>
        </criteria>
        <criteria operator="AND" comment="vulnerable IIS 5.0 on Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft IIS 5.0 is installed" definition_ref="oval:org.mitre.oval:def:731"/>
          <criterion comment="the version of w3svc.dll is less than 5.0.2195.5269" test_ref="oval:org.mitre.oval:tst:42203"/>
          <criterion comment="FTP Enabled" test_ref="oval:org.mitre.oval:tst:3074"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:125" class="vulnerability" version="1">
      <metadata>
        <title>HTML Help ActiveX Control Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0214" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0214"/>
        <description>The HTML Help ActiveX control (Hhctrl.ocx) in Microsoft Windows 2000 SP3, XP SP2 and Professional, 2003 SP1 allows remote attackers to execute arbitrary code via unspecified functions, related to uninitialized parameters.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-02-14T09:49:32">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-02-16T21:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:16:46.946-04:00">INTERIM</status_change>
            <status_change date="2007-04-10T13:44:19.992-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Win2K,SP4" operator="AND">
          <extend_definition comment="Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Hhctrl.ocx is less than 5.2.3790.620" test_ref="oval:org.mitre.oval:tst:196"/>
        </criteria>
        <criteria comment="WinXP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of Hhctrl.ocx is less than 5.2.3790.2847" test_ref="oval:org.mitre.oval:tst:3154"/>
        </criteria>
        <criteria comment="WinXP,SP1 (64-bit)" operator="AND">
          <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="the version of Hhctrl.ocx is less than 5.2.3790.2847" test_ref="oval:org.mitre.oval:tst:3154"/>
        </criteria>
        <criteria comment="S03-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="the version of Hhctrl.ocx is less than 5.2.3790.620" test_ref="oval:org.mitre.oval:tst:196"/>
        </criteria>
        <criteria comment="S03,SP1" operator="AND">
          <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of Hhctrl.ocx is less than 5.2.3790.2847" test_ref="oval:org.mitre.oval:tst:3154"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12490" version="3" class="vulnerability">
      <metadata>
        <title>Denial of service via FTP status request</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0073" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0073"/>
        <description>The FTP service in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows attackers who have established an FTP session to cause a denial of service via a specially crafted status request containing glob characters.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-16T12:00:00.000-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2011-01-12T13:28:44.271-05:00">DRAFT</status_change>
            <status_change date="2011-01-31T04:00:12.810-05:00">INTERIM</status_change>
            <status_change date="2011-02-21T04:00:37.483-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="vulnerable IIS 4.0 on Windows NT">
          <extend_definition comment="Microsoft Windows NT is installed" definition_ref="oval:org.mitre.oval:def:36"/>
          <extend_definition comment="Microsoft IIS 4.0 is installed" definition_ref="oval:org.mitre.oval:def:12482"/>
          <criterion comment="the version of w3svc.dll is less than 4.2.775.1" test_ref="oval:org.mitre.oval:tst:42232"/>
          <criterion comment="FTP Enabled" test_ref="oval:org.mitre.oval:tst:3074"/>
        </criteria>
        <criteria operator="AND" comment="vulnerable IIS 5.0 on Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft IIS 5.0 is installed" definition_ref="oval:org.mitre.oval:def:731"/>
          <criterion comment="the version of w3svc.dll is less than 5.0.2195.5269" test_ref="oval:org.mitre.oval:tst:42203"/>
          <criterion comment="FTP Enabled" test_ref="oval:org.mitre.oval:tst:3074"/>
        </criteria>
        <criteria operator="AND" comment="vulnerable IIS 5.1 on Windows XP">
          <extend_definition comment="Microsoft Windows XP is installed" definition_ref="oval:org.mitre.oval:def:105"/>
          <extend_definition comment="Microsoft IIS 5.1 is installed" definition_ref="oval:org.mitre.oval:def:460"/>
          <criterion comment="the version of w3svc.dll is less than 5.1.2600.41" test_ref="oval:org.mitre.oval:tst:41232"/>
          <criterion comment="FTP Enabled" test_ref="oval:org.mitre.oval:tst:3074"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12489" version="3" class="vulnerability">
      <metadata>
        <title>Denial of service vulnerability in PHP 5.2 before 5.2.15 and 5.3 before 5.3.4 in IMAP extension</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>PHP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-4150" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4150"/>
        <description>Double free vulnerability in the imap_do_open function in the IMAP extension (ext/imap/php_imap.c) in PHP 5.2 before 5.2.15 and 5.3 before 5.3.4 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-03-22T16:21:49">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-03-22T13:47:57.717-04:00">DRAFT</status_change>
            <status_change date="2011-04-11T04:00:09.200-04:00">INTERIM</status_change>
            <status_change date="2011-05-02T04:00:07.444-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="PHP is installed" definition_ref="oval:org.mitre.oval:def:12410"/>
        <criterion comment="Check if the version of PHP is 5.2 before 5.2.15 or 5.3 before 5.3.4" test_ref="oval:org.mitre.oval:tst:42069"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1248" version="3" class="vulnerability">
      <metadata>
        <title>OLE Automation Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Visual Basic 6.0</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2224" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2224"/>
        <description>Object linking and embedding (OLE) Automation, as used in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Office 2004 for Mac, and Visual Basic 6.0 allows remote attackers to execute arbitrary code via the substringData method on a TextNode object, which causes an integer overflow that leads to a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-15T13:16:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-08-15T16:59:48.715-04:00">DRAFT</status_change>
            <modified comment="Corrected cve reference." date="2007-08-28T07:44:00.451-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-09-12T15:04:55.697-04:00">INTERIM</status_change>
            <status_change date="2007-09-27T08:57:39.327-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1248 - Correcting incorrect references to 64-bit Itanium XP." date="2012-08-23T17:47:00.168-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-08-23T17:52:57.956-04:00">INTERIM</status_change>
            <status_change date="2012-09-10T04:00:05.729-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Windows 2000 SP4 and Oleaut32.dll version is less than 2.40.4531.0">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Oleaut32.dll version is less than 2.40.4531.0" test_ref="oval:org.mitre.oval:tst:4203"/>
        </criteria>
        <criteria comment="Windows XP SP2 and Oleaut32.dll version is less than 5.1.2600.3139">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="Oleaut32.dll version is less than 5.1.2600.3139" test_ref="oval:org.mitre.oval:tst:3235"/>
        </criteria>
        <criteria comment="Windows XP SP1 (64-bit) and Oleaut32.dll version is less than 5.2.3790.2955">
          <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="Oleaut32.dll version is less than 5.2.3790.2955" test_ref="oval:org.mitre.oval:tst:3380"/>
        </criteria>
        <criteria comment="Windows XP SP2 (64-bit) and Oleaut32.dll version is less than 5.2.3790.4098">
          <criterion comment="Oleaut32.dll version is less than 5.2.3790.4098" test_ref="oval:org.mitre.oval:tst:4174"/>
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
        </criteria>
        <criteria comment="Windows Server 2003 SP1 and Oleaut32.dll version is less than 5.2.3790.2955">
          <criteria operator="OR" comment="Windows Server 2003 SP1">
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1205"/>
          </criteria>
          <criterion comment="Oleaut32.dll version is less than 5.2.3790.2955" test_ref="oval:org.mitre.oval:tst:3380"/>
        </criteria>
        <criteria comment="Windows Server 2003 SP2 and Oleaut32.dll version is less than 5.2.3790.4098">
          <criteria operator="OR" comment="Windows Server 2003 SP2">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="Oleaut32.dll version is less than 5.2.3790.4098" test_ref="oval:org.mitre.oval:tst:4174"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1205" version="11" class="inventory">
      <metadata>
        <title>Microsoft Windows Server 2003 SP1 for Itanium is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_server_2003::sp1:itanium"/>
        <description>A version of Microsoft Windows Server 2003 SP1 for Itanium is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-03-05T09:00:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2007-03-05T09:00:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:16:45.596-04:00">INTERIM</status_change>
            <status_change date="2007-04-10T13:44:19.196-04:00">ACCEPTED</status_change>
            <modified comment="Changed the CPE reference" date="2008-04-04T11:17:00.275-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2008-04-04T11:22:23.300-04:00">INTERIM</status_change>
            <status_change date="2008-04-21T04:00:10.886-04:00">ACCEPTED</status_change>
            <modified comment="Changed the tests for ia64, SP1, and windows to be case insensitive and replaced the test for Windows 5.2 with a new test for 2003" date="2009-12-02T16:05:00.749-04:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <status_change date="2009-12-02T16:05:00.749-04:00">INTERIM</status_change>
            <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:56:00.085-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <modified comment="Updating regex to include parenthesis" date="2009-12-08T17:31:00.354-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <status_change date="2010-01-04T04:01:24.866-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1205 - Updated Windows 2003 Server CPE names." date="2011-03-29T13:48:00.699-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-03-29T13:51:35.271-04:00">INTERIM</status_change>
            <status_change date="2011-04-18T04:00:08.296-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:46:01.264-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:00:32.710-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1205 - Modifications vary from minor OVAL title/description changes to suggesting an alternative CPE name to use." date="2011-09-28T11:29:00.976-04:00">
              <contributor organization="The MITRE Corporation">David Rothenberg</contributor>
            </modified>
            <status_change date="2011-09-28T11:33:47.217-04:00">INTERIM</status_change>
            <status_change date="2011-10-17T04:00:07.293-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criterion comment="Windows Server 2003 is installed" test_ref="oval:org.mitre.oval:tst:11145"/>
        <criterion comment="a version of Windows for the ia64 architecture is installed" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="Win2K/XP/2003/Vista service pack 1 is installed" test_ref="oval:org.mitre.oval:tst:2843"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1247" version="3" class="vulnerability">
      <metadata>
        <title>Mozilla Privilege Escalation Using a JavaScript Function's Cloned Parent</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1734" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1734"/>
        <description>Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to execute arbitrary code by using the Object.watch method to access the "clone parent" internal function.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-07T09:05:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:15.909-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:1133" date="2007-02-26T08:08:00.208-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-26T08:09:14.985-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:1135" date="2007-02-26T08:21:00.993-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:1136" date="2007-02-26T08:24:00.848-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:1138" date="2007-02-26T08:25:00.405-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:2283" date="2007-02-26T08:29:00.407-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:2284" date="2007-02-26T08:30:00.724-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:46.565-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:881" date="2007-04-23T12:05:00.811-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:12:53.062-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:882" date="2007-04-23T12:05:00.939-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in obj:883" date="2007-04-23T12:05:00.804-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in obj:1385" date="2007-04-23T12:05:00.430-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:10:52.674-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1268"/>
          <criterion comment="Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1267"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Thunderbird version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1266"/>
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1265"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.12 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1264"/>
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1263"/>
        </criteria>
        <criteria operator="AND" comment="A pre-release of SeaMonkey 1.0 is installed">
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2439"/>
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2438"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1244" version="6" class="vulnerability">
      <metadata>
        <title>Plug and Play User Data Validation Vulnerability (Windows 2000)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2120" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2120"/>
        <description>Stack-based buffer overflow in the Plug and Play (PnP) service (UMPNPMGR.DLL) in Microsoft Windows 2000 SP4, and XP SP1 and SP2, allows remote or local authenticated attackers to execute arbitrary code via a large number of "\" (backslash) characters in a registry key name, which triggers the overflow in a wsprintfW function call.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-31T12:00:00.000-04:00" comment="removed an incorrect leading ^ from the value entity of ste:2402">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-31T00:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:15.640-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1244 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:05:27.402-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:00:39.436-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Windows 2000 is installed" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="Win2K/XP/2003 service pack 4 is installed" test_ref="oval:org.mitre.oval:tst:2569"/>
        <criterion comment="umpnpmgr.dll is less than 5.0.2195.7069" test_ref="oval:org.mitre.oval:tst:1043"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12413" version="3" class="vulnerability">
      <metadata>
        <title>Buffer overrun in HTR ISAPI extension</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows NT</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0071" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0071"/>
        <description>Buffer overflow in the ism.dll ISAPI extension that implements HTR scripting in Internet Information Server (IIS) 4.0 and 5.0 allows attackers to cause a denial of service or execute arbitrary code via HTR requests with long variable names.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-16T12:00:00.000-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2011-01-12T13:28:45.706-05:00">DRAFT</status_change>
            <status_change date="2011-01-31T04:00:11.878-05:00">INTERIM</status_change>
            <status_change date="2011-02-21T04:00:30.129-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="vulnerable IIS 4.0 on Windows NT">
          <extend_definition comment="Microsoft Windows NT is installed" definition_ref="oval:org.mitre.oval:def:36"/>
          <extend_definition comment="Microsoft IIS 4.0 is installed" definition_ref="oval:org.mitre.oval:def:12482"/>
          <criterion comment="the version of w3svc.dll is less than 4.2.775.1" test_ref="oval:org.mitre.oval:tst:42232"/>
          <criterion comment="FTP Enabled" test_ref="oval:org.mitre.oval:tst:3074"/>
        </criteria>
        <criteria operator="AND" comment="vulnerable IIS 5.0 on Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft IIS 5.0 is installed" definition_ref="oval:org.mitre.oval:def:731"/>
          <criterion comment="the version of w3svc.dll is less than 5.0.2195.5269" test_ref="oval:org.mitre.oval:tst:42203"/>
          <criterion comment="FTP Enabled" test_ref="oval:org.mitre.oval:tst:3074"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12407" version="3" class="vulnerability">
      <metadata>
        <title>Buffer Overrun in ASP Server-Side Include Function</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0149" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0149"/>
        <description>Buffer overflow in ASP Server-Side Include Function in IIS 4.0, 5.0 and 5.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via long file names.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-16T12:00:00.000-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2011-01-12T13:28:45.433-05:00">DRAFT</status_change>
            <status_change date="2011-01-31T04:00:10.802-05:00">INTERIM</status_change>
            <status_change date="2011-02-21T04:00:28.930-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="vulnerable IIS 4.0 on Windows NT">
          <extend_definition comment="Microsoft Windows NT is installed" definition_ref="oval:org.mitre.oval:def:36"/>
          <extend_definition comment="Microsoft IIS 4.0 is installed" definition_ref="oval:org.mitre.oval:def:12482"/>
          <criterion comment="the version of w3svc.dll is less than 4.2.775.1" test_ref="oval:org.mitre.oval:tst:42232"/>
          <criterion comment="FTP Enabled" test_ref="oval:org.mitre.oval:tst:3074"/>
        </criteria>
        <criteria operator="AND" comment="vulnerable IIS 5.0 on Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft IIS 5.0 is installed" definition_ref="oval:org.mitre.oval:def:731"/>
          <criterion comment="the version of w3svc.dll is less than 5.0.2195.5269" test_ref="oval:org.mitre.oval:tst:42203"/>
          <criterion comment="FTP Enabled" test_ref="oval:org.mitre.oval:tst:3074"/>
        </criteria>
        <criteria operator="AND" comment="vulnerable IIS 5.1 on Windows XP">
          <extend_definition comment="Microsoft Windows XP is installed" definition_ref="oval:org.mitre.oval:def:105"/>
          <extend_definition comment="Microsoft IIS 5.1 is installed" definition_ref="oval:org.mitre.oval:def:460"/>
          <criterion comment="the version of w3svc.dll is less than 5.1.2600.41" test_ref="oval:org.mitre.oval:tst:41232"/>
          <criterion comment="FTP Enabled" test_ref="oval:org.mitre.oval:tst:3074"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1240" version="7" class="vulnerability">
      <metadata>
        <title>EMF Rendering Denial of Service Vulnerability (Windows 2000)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0803" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0803"/>
        <description>The GetEnhMetaFilePaletteEntries API in GDI32.DLL in Windows 2000 allows remote attackers to cause a denial of service (application crash) via a crafted Enhanced Metafile (EMF) file that causes invalid (1) end, (2) emreof, or (3) palent offsets to be used, aka "Enhanced Metafile Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-09T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-11-10T07:06:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-16T01:04:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed regex in ste:2889.  Implemented by Matthew Wojcik." date="2007-03-06T18:19:00.507-05:00">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2007-03-06T18:21:08.346-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:16:46.368-04:00">ACCEPTED</status_change>
            <modified date="2009-10-09T16:16:46.368-04:00" comment="Removed use of deprecated test">
              <contributor organization="The MITRE Corporation">Mike Lah</contributor>
            </modified>
            <status_change date="2009-10-12T04:00:20.441-04:00">INTERIM</status_change>
            <status_change date="2009-11-02T04:00:02.336-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1240 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:06:30.413-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:00:39.048-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criteria operator="OR" comment="version of Gdi32.dll is less than 5.0.2195.7069 OR the version of Mf3216.dll is less than 5.0.2195.6898">
          <criterion comment="the version of Gdi32.dll is less than 5.0.2195.7069" test_ref="oval:org.mitre.oval:tst:1227"/>
          <criterion comment="the version of mf3216.dll is less than 5.0.2195.6898" test_ref="oval:org.mitre.oval:tst:1398"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12393" version="3" class="vulnerability">
      <metadata>
        <title>Vulnerability in the iconv_mime_decode_headers function in the Iconv extension in PHP before 5.3.4</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>PHP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-4699" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4699"/>
        <description>The iconv_mime_decode_headers function in the Iconv extension in PHP before 5.3.4 does not properly handle encodings that are unrecognized by the iconv and mbstring (aka Multibyte String) implementations, which allows remote attackers to trigger an incomplete output array, and possibly bypass spam detection or have unspecified other impact, via a crafted Subject header in an e-mail message, as demonstrated by the ks_c_5601-1987 character set.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-03-22T16:21:49">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-03-22T13:47:56.885-04:00">DRAFT</status_change>
            <status_change date="2011-04-11T04:00:08.515-04:00">INTERIM</status_change>
            <status_change date="2011-05-02T04:00:07.109-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="PHP is installed" definition_ref="oval:org.mitre.oval:def:12410"/>
        <criterion comment="Check if the version of PHP is less than 5.3.4" test_ref="oval:org.mitre.oval:tst:42273"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1239" version="5" class="vulnerability">
      <metadata>
        <title>IE5.01,SP4 PNG Image Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1211" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1211"/>
        <description>Buffer overflow in the PNG image rendering component of Microsoft Internet Explorer allows remote attackers to execute arbitrary code via a crafted PNG file.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-22T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-06-22T12:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-17T04:13:00.000-04:00" comment="Fixed registry_object obj:1557 by moving PNGFilter.CoPNGFilter from name to end of key, and setting xsi:nil to true on name.  Modified by Harvey Rubinovitz">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2006-10-17T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-11-14T08:57:51.888-05:00">ACCEPTED</status_change>
            <modified comment="Fixed ste:2614: set datatype to version.  Implemented by Harvey Rubinovitz." date="2007-01-25T16:54:00.319-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-25T16:59:43.350-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:37.230-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:49.509-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:11.624-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3828.2700" negate="false" test_ref="oval:org.mitre.oval:tst:2359"/>
          <criterion comment="the patch kb883939 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2750"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="PNG image rendering enabled in Internet Explorer" negate="false" test_ref="oval:org.mitre.oval:tst:2749"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12374" version="3" class="vulnerability">
      <metadata>
        <title>Information disclosure vulnerability in HTTP BIO connector in Apache Tomcat 7.0.x through 7.0.11</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Apache Tomcat</product>
        </affected>
        <reference ref_id="CVE-2011-1475" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1475" source="CVE"/>
        <description>The HTTP BIO connector in Apache Tomcat 7.0.x before 7.0.12 does not properly handle HTTP pipelining, which allows remote attackers to read responses intended for other clients in opportunistic circumstances by examining the application data in HTTP packets, related to "a mix-up of responses for requests from different users."</description>
        <oval_repository>
          <dates>
            <submitted date="2011-05-04T09:29:30-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-05-06T15:23:47.149-04:00">DRAFT</status_change>
            <status_change date="2011-05-23T04:00:10.509-04:00">INTERIM</status_change>
            <status_change date="2011-06-13T04:00:05.510-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Apache Tomcat is installed" definition_ref="oval:org.mitre.oval:def:12401"/>
        <criterion comment="Check if Apache Tomcat version is in range 7.0 through 7.0.11" test_ref="oval:org.mitre.oval:tst:42406"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12401" version="3" class="inventory">
      <metadata>
        <title>Apache Tomcat is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Apache Tomcat</product>
        </affected>
        <reference ref_id="cpe:/a:apache:tomcat" source="CPE"/>
        <description>Apache Tomcat is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2010-12-17T14:41:13">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-12-21T11:26:47.171-05:00">DRAFT</status_change>
            <status_change date="2011-01-10T04:00:16.630-05:00">INTERIM</status_change>
            <status_change date="2011-01-31T04:00:10.533-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Apache Tomcat is installed" test_ref="oval:org.mitre.oval:tst:41921"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12364" version="8" class="vulnerability">
      <metadata>
        <title>Information disclosure vulnerability in Internet Explorer due to HTML element</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3472" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3472"/>
        <description>Microsoft Internet Explorer 6 and 7 does not properly determine the domain or security zone of origin of web script, which allows remote attackers to bypass the intended cross-domain security policy, and execute arbitrary code or obtain sensitive information, via a crafted HTML document, aka "HTML Element Cross-Domain Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2011-10-25T13:27:14">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-10-28T20:26:13.720-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:8644 - ste:4424 is updated to correct version. added 5 new definitions for ms08-058 are not in the repository" date="2011-10-28T20:15:00.656-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2011-11-14T04:00:07.829-05:00">INTERIM</status_change>
            <status_change date="2011-12-05T04:00:05.261-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4503 - modified states" date="2014-02-13T12:23:00.044-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:24:14.109-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:00:26.003-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:12364 - extended definitions of OS are without SP checks" date="2014-07-28T17:57:00.076-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:59:07.834-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:00:26.699-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 and Win 2KSo4">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2800.1615" test_ref="oval:org.mitre.oval:tst:8845"/>
        </criteria>
        <criteria operator="AND" comment="Win XP X86 and IE6">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3429" test_ref="oval:org.mitre.oval:tst:9320"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
        </criteria>
        <criteria operator="AND" comment="Win XP X86 and IE6">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.5659" test_ref="oval:org.mitre.oval:tst:9099"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
        </criteria>
        <criteria operator="AND" comment="IE7 and Win XP or Win 2K3">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="Win XP or Win 2K3">
            <extend_definition comment="Microsoft Windows XP is installed" definition_ref="oval:org.mitre.oval:def:105"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR / GDR">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16735" test_ref="oval:org.mitre.oval:tst:8577"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.20900" test_ref="oval:org.mitre.oval:tst:44256"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE6 and Win 2K3 or Win XP X64">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.3194" test_ref="oval:org.mitre.oval:tst:8956"/>
          <criteria operator="OR" comment="Win XP X64 or Win 2K3">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 2K3 or Win XP X64 and IE6">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.3790.4357" test_ref="oval:org.mitre.oval:tst:8902"/>
          <criteria operator="OR" comment="Win 2K3 or Win XP X64">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE7 and Vista">
          <extend_definition comment="Microsoft Windows Vista is installed" definition_ref="oval:org.mitre.oval:def:228"/>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criterion comment="Mshtml.dll version is less than 7.0.6000.16757" test_ref="oval:org.mitre.oval:tst:8644"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Mshtml.dll version is greater than 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:9441"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6000.20927" test_ref="oval:org.mitre.oval:tst:9560"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 2K8 / Vista and IE7">
          <criteria operator="OR" comment="Win 2K8 / Vista">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR / GDR">
            <criterion comment="Mshtml.dll version is less than 7.0.6001.18148" test_ref="oval:org.mitre.oval:tst:9509"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Mshtml.dll version is greater than or equal to 7.0.6001.22000" test_ref="oval:org.mitre.oval:tst:42152"/>
              <criterion comment="Mshtml.dll version is less than 7.0.6001.22260" test_ref="oval:org.mitre.oval:tst:9350"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
        </criteria>
        <criteria operator="AND" comment="Win 2K8 ia 64">
          <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          <criteria operator="OR" comment="Check for LDR / GDR">
            <criterion comment="Check if the version of mshtml.dll is less than 7.0.6001.18137" test_ref="oval:org.mitre.oval:tst:44400"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Mshtml.dll version is less than 7.0.6001.22260" test_ref="oval:org.mitre.oval:tst:9350"/>
              <criterion comment="Mshtml.dll version is greater than or equal to 7.0.6001.22000" test_ref="oval:org.mitre.oval:tst:42152"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:730" version="11" class="inventory">
      <metadata>
        <title>Microsoft Windows Server 2003 (x64) is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_server_2003:::x64"/>
        <description>A version of Microsoft Windows Server 2003 (x64) is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-03-05T09:00:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2007-03-05T09:00:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:17:25.745-04:00">INTERIM</status_change>
            <status_change date="2007-04-10T13:44:28.055-04:00">ACCEPTED</status_change>
            <modified comment="Changed the CPE reference" date="2008-04-04T11:17:00.114-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2008-04-04T11:29:06.138-04:00">INTERIM</status_change>
            <status_change date="2008-04-21T04:00:24.051-04:00">ACCEPTED</status_change>
            <modified comment="Changed registry check for amd64 to be a case insensitive equals" date="2009-09-04T10:48:00.140-05:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2009-09-14T04:00:18.760-04:00">INTERIM</status_change>
            <status_change date="2009-10-05T04:00:07.341-04:00">ACCEPTED</status_change>
            <modified comment="Changed registry check for amd64 to be case insensitive equals" date="2009-11-19T18:33:00.593-05:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2009-11-19T18:35:10.246-05:00">INTERIM</status_change>
            <modified comment="Changed the test for windows to be case insensitive and replaced the test for Windows 5.2 with a new test for 2003" date="2009-12-02T16:05:00.749-04:00">
              <contributor organization="National Institute of Standards and Technology">Tim
                Harrison</contributor>
            </modified>
            <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:56:00.085-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim
                Harrison</contributor>
            </modified>
            <modified comment="Updating regex to include parenthesis" date="2009-12-08T17:31:00.354-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim
                Harrison</contributor>
            </modified>
            <status_change date="2009-12-28T04:00:41.772-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:730 - Updated Windows 2003 Server CPE names." date="2011-03-29T13:48:00.699-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-03-29T13:51:33.974-04:00">INTERIM</status_change>
            <status_change date="2011-04-18T04:00:41.337-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:730 - Modifications vary from minor OVAL title/description changes to suggesting an alternative CPE name to use." date="2011-09-28T11:29:00.976-04:00">
              <contributor organization="The MITRE Corporation">David Rothenberg</contributor>
            </modified>
            <status_change date="2011-09-28T11:33:46.406-04:00">INTERIM</status_change>
            <status_change date="2011-10-17T04:00:24.757-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:3180 - new inventory for SQL Server 2008 R2 64-bit" date="2013-07-05T09:33:00.078-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-05T09:37:54.076-04:00">INTERIM</status_change>
            <status_change date="2013-07-22T04:03:13.461-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criterion comment="Windows Server 2003 is installed" test_ref="oval:org.mitre.oval:tst:11145"/>
        <criterion comment="a version of Windows for the x64 architecture is installed" test_ref="oval:org.mitre.oval:tst:3653"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:396" version="11" class="inventory">
      <metadata>
        <title>Microsoft Windows Server 2003 (ia64) Gold is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_server_2003::-:itanium"/>
        <description>A version of Microsoft Windows Server 2003 (ia64) Gold is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-03-05T09:00:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2007-03-05T09:00:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:17:18.086-04:00">INTERIM</status_change>
            <status_change date="2007-04-10T13:44:26.147-04:00">ACCEPTED</status_change>
            <modified comment="Changed the CPE reference" date="2008-04-04T11:17:00.401-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2008-04-04T11:26:52.428-04:00">INTERIM</status_change>
            <status_change date="2008-04-21T04:00:18.926-04:00">ACCEPTED</status_change>
            <modified comment="Changed the tests for ia64 and windows to be case insensitive and replaced the test for Windows 5.2 with a new test for 2003" date="2009-12-02T16:05:00.749-04:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <status_change date="2009-12-02T16:05:00.749-04:00">INTERIM</status_change>
            <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:56:00.085-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <modified comment="Updating regex to include parenthesis" date="2009-12-08T17:31:00.354-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <status_change date="2009-12-28T04:00:12.166-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:396 - Updated Windows 2003 Server CPE names." date="2011-03-29T13:48:00.699-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-03-29T13:51:31.342-04:00">INTERIM</status_change>
            <status_change date="2011-04-18T04:00:36.861-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:16.949-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:02:55.770-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:396 - Updated CPEs." date="2011-10-04T13:20:00.685-04:00">
              <contributor organization="The MITRE Corporation">David Rothenberg</contributor>
            </modified>
            <status_change date="2011-10-04T13:40:39.977-04:00">INTERIM</status_change>
            <status_change date="2011-10-24T04:00:09.002-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criterion comment="Windows Server 2003 is installed" test_ref="oval:org.mitre.oval:tst:11145"/>
        <criterion comment="a version of Windows for the ia64 architecture is installed" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion negate="true" comment="Win2K/XP/2003 is patched" test_ref="oval:org.mitre.oval:tst:2437"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:228" version="5" class="inventory">
      <metadata>
        <title>Microsoft Windows Vista is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_vista"/>
        <description>The operating system installed on the system is Microsoft Windows Vista</description>
        <oval_repository>
          <dates>
            <submitted date="2007-02-13T12:46:06">
              <contributor organization="Secure Elements, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2007-02-13T14:53:06-04:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:17:12.775-04:00">INTERIM</status_change>
            <status_change date="2007-04-13T15:13:39.760-04:00">ACCEPTED</status_change>
            <modified comment="Added CPE reference." date="2007-04-30T07:48:00.893-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-30T07:56:25.929-04:00">INTERIM</status_change>
            <status_change date="2007-05-23T15:05:40.286-04:00">ACCEPTED</status_change>
            <modified comment="Vista test updated because of the conflictions with Server 2008" date="2008-03-26T10:51:02.210-04:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2008-03-31T04:00:22.690-04:00">INTERIM</status_change>
            <modified comment="Changed the CPE reference" date="2008-04-04T11:17:00.315-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2008-04-21T04:00:18.129-04:00">ACCEPTED</status_change>
            <modified comment="Changed the tests for Vista and windows to be case insensitive" date="2009-12-02T16:05:00.749-04:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <status_change date="2009-12-02T16:05:00.749-04:00">INTERIM</status_change>
            <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:55:00.401-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <modified comment="Updating regex to include parenthesis" date="2009-12-08T17:31:00.669-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <status_change date="2009-12-28T04:00:11.598-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criterion comment="Windows Vista is installed" test_ref="oval:org.mitre.oval:tst:7914"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2041" version="6" class="inventory">
      <metadata>
        <title>Microsoft Windows Vista x64 Edition is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_vista:::x64"/>
        <description>The operating system installed on the system is Microsoft Windows Vista x64
          Edition</description>
        <oval_repository>
          <dates>
            <submitted date="2007-04-11T11:27:37.975-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2007-04-11T11:27:37.975-04:00">DRAFT</status_change>
            <status_change date="2007-04-30T08:18:48.676-04:00">INTERIM</status_change>
            <status_change date="2007-05-23T15:05:38.024-04:00">ACCEPTED</status_change>
            <modified comment="Vista test updated because of the conflictions with Server 2008" date="2008-03-26T10:51:02.210-04:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2008-03-31T04:00:20.760-04:00">INTERIM</status_change>
            <modified comment="Changed the CPE reference" date="2008-04-04T11:17:00.142-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2008-04-21T04:00:15.809-04:00">ACCEPTED</status_change>
            <modified comment="Changed registry check for amd64 to be a case insensitive equals" date="2009-09-04T10:48:00.140-05:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2009-09-07T04:00:24.286-04:00">INTERIM</status_change>
            <status_change date="2009-09-28T04:00:02.523-04:00">ACCEPTED</status_change>
            <modified comment="Changed registry check for amd64 to be case insensitive equals" date="2009-11-19T18:33:00.593-05:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2009-11-19T18:35:10.039-05:00">INTERIM</status_change>
            <modified comment="Changed the tests for Vista and windows to be case insensitive" date="2009-12-02T16:05:00.749-04:00">
              <contributor organization="National Institute of Standards and Technology">Tim
                Harrison</contributor>
            </modified>
            <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:55:00.401-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim
                Harrison</contributor>
            </modified>
            <modified comment="Updating regex to include parenthesis" date="2009-12-08T17:31:00.669-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim
                Harrison</contributor>
            </modified>
            <status_change date="2010-01-04T04:01:29.449-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:3180 - new inventory for SQL Server 2008 R2 64-bit" date="2013-07-05T09:33:00.078-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-05T09:37:49.347-04:00">INTERIM</status_change>
            <status_change date="2013-07-22T04:03:03.104-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criterion comment="Windows Vista is installed" test_ref="oval:org.mitre.oval:tst:7914"/>
        <criterion comment="a version of Windows for the x64 architecture is installed" test_ref="oval:org.mitre.oval:tst:3653"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1870" version="8" class="inventory">
      <metadata>
        <title>Microsoft Windows Server 2003 (32-bit) is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_server_2003:::x86"/>
        <description>A version of Microsoft Windows Server 2003 (32-bit) is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-06-12T03:29:54.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-06-12T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-06-29T09:41:59.800-04:00">INTERIM</status_change>
            <status_change date="2007-07-16T09:55:11.155-04:00">ACCEPTED</status_change>
            <modified comment="Changed the CPE reference" date="2008-04-04T11:17:00.141-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2008-04-04T11:24:54.166-04:00">INTERIM</status_change>
            <status_change date="2008-04-21T04:00:14.944-04:00">ACCEPTED</status_change>
            <modified comment="Replaced negation of test for x64 with a case insensitive test for x86 and the test for Windows 5.2 with a new test for 2003, and changed the test for windows to be case insensitive" date="2009-12-02T16:05:00.749-04:00">
              <contributor organization="National Institute of Standards and Technology">Tim
                Harrison</contributor>
            </modified>
            <status_change date="2009-12-02T16:05:00.749-04:00">INTERIM</status_change>
            <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:56:00.085-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim
                Harrison</contributor>
            </modified>
            <modified comment="Updating regex to include parenthesis" date="2009-12-08T17:31:00.354-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim
                Harrison</contributor>
            </modified>
            <status_change date="2009-12-28T04:00:09.084-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1870 - Updated Windows 2003 Server CPE names." date="2011-03-29T13:48:00.699-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-03-29T13:51:29.954-04:00">INTERIM</status_change>
            <status_change date="2011-04-18T04:00:35.523-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1870 - Modifications vary from minor OVAL title/description changes to suggesting an alternative CPE name to use." date="2011-09-28T11:29:00.976-04:00">
              <contributor organization="The MITRE Corporation">David Rothenberg</contributor>
            </modified>
            <status_change date="2011-09-28T11:33:13.661-04:00">INTERIM</status_change>
            <status_change date="2011-10-17T04:00:13.688-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criterion comment="Windows Server 2003 is installed" test_ref="oval:org.mitre.oval:tst:11145"/>
        <criterion comment="a version of Windows for the x86 architecture is installed" test_ref="oval:org.mitre.oval:tst:3823"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15247" version="5" class="inventory">
      <metadata>
        <title>Microsoft Windows XP x64 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_xp::x64"/>
        <description>A version of Microsoft Windows XP x64 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-03-09T12:23:46">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-06-19T12:04:45.447-04:00">DRAFT</status_change>
            <status_change date="2012-07-09T04:00:13.684-04:00">INTERIM</status_change>
            <status_change date="2012-07-30T04:00:17.582-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:3180 - new inventory for SQL Server 2008 R2 64-bit" date="2013-07-05T09:33:00.078-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-05T09:37:55.269-04:00">INTERIM</status_change>
            <status_change date="2013-07-22T04:00:15.576-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criterion comment="Windows XP is installed" test_ref="oval:org.mitre.oval:tst:11179"/>
        <criterion comment="a version of Windows for the x64 architecture is installed" test_ref="oval:org.mitre.oval:tst:3653"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1353" version="4" class="inventory">
      <metadata>
        <title>Microsoft Windows XP (32-bit) is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_xp:::x86"/>
        <description>The operating system installed on the system is Microsoft Windows XP (32-bit).</description>
        <oval_repository>
          <dates>
            <submitted date="2007-06-12T03:29:54.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-06-12T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-06-29T09:41:56.719-04:00">INTERIM</status_change>
            <status_change date="2007-07-16T09:55:07.230-04:00">ACCEPTED</status_change>
            <modified comment="Changed the CPE reference" date="2008-04-04T11:17:00.731-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2008-04-04T11:22:47.753-04:00">INTERIM</status_change>
            <status_change date="2008-04-21T04:00:12.066-04:00">ACCEPTED</status_change>
            <modified comment="Replaced negation of test for x64 with a case insensitive test for x86, changed the test for windows to be case insensitive, removed extension of definition 'oval:org.mitre.oval:def:105', and added tests for windows and XP" date="2009-12-02T16:05:00.749-04:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <status_change date="2009-12-02T16:05:00.749-04:00">INTERIM</status_change>
            <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:56:00.359-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <modified comment="Updating regex to include parenthesis" date="2009-12-08T17:32:00.792-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <status_change date="2009-12-28T04:00:07.561-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criterion comment="Windows XP is installed" test_ref="oval:org.mitre.oval:tst:11179"/>
        <criterion comment="a version of Windows for the x86 architecture is installed" test_ref="oval:org.mitre.oval:tst:3823"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12356" version="3" class="vulnerability">
      <metadata>
        <title>Cross-site Scripting in IIS Help File search facility</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0074" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0074"/>
        <description>Cross-site scripting vulnerability in Help File search facility for Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to embed scripts into another user's session.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-16T12:00:00.000-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2011-01-12T13:28:46.231-05:00">DRAFT</status_change>
            <status_change date="2011-01-31T04:00:09.878-05:00">INTERIM</status_change>
            <status_change date="2011-02-21T04:00:25.297-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="vulnerable IIS 4.0 on Windows NT">
          <extend_definition comment="Microsoft Windows NT is installed" definition_ref="oval:org.mitre.oval:def:36"/>
          <extend_definition comment="Microsoft IIS 4.0 is installed" definition_ref="oval:org.mitre.oval:def:12482"/>
          <criterion comment="the version of w3svc.dll is less than 4.2.775.1" test_ref="oval:org.mitre.oval:tst:42232"/>
          <criterion comment="FTP Enabled" test_ref="oval:org.mitre.oval:tst:3074"/>
        </criteria>
        <criteria operator="AND" comment="vulnerable IIS 5.0 on Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft IIS 5.0 is installed" definition_ref="oval:org.mitre.oval:def:731"/>
          <criterion comment="the version of w3svc.dll is less than 5.0.2195.5269" test_ref="oval:org.mitre.oval:tst:42203"/>
          <criterion comment="FTP Enabled" test_ref="oval:org.mitre.oval:tst:3074"/>
        </criteria>
        <criteria operator="AND" comment="vulnerable IIS 5.1 on Windows XP">
          <extend_definition comment="Microsoft Windows XP is installed" definition_ref="oval:org.mitre.oval:def:105"/>
          <extend_definition comment="Microsoft IIS 5.1 is installed" definition_ref="oval:org.mitre.oval:def:460"/>
          <criterion comment="the version of w3svc.dll is less than 5.1.2600.41" test_ref="oval:org.mitre.oval:tst:41232"/>
          <criterion comment="FTP Enabled" test_ref="oval:org.mitre.oval:tst:3074"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12355" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft Internet Explorer PDF Printing Information Disclosure</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4073" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4073"/>
        <description>The printing functionality in Microsoft Internet Explorer 8 allows remote attackers to discover a local pathname, and possibly a local username, by reading the dc:title element of a PDF document that was generated from a local web page.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-06-28T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2011-07-05T22:14:57.740-04:00">DRAFT</status_change>
            <status_change date="2011-07-25T04:00:08.947-04:00">INTERIM</status_change>
            <status_change date="2011-08-15T04:00:05.923-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
        <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
        <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1235" version="4" class="vulnerability">
      <metadata>
        <title>IE6,SP1 COM Object Instantiation Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1990" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1990"/>
        <description>Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not ActiveX controls, including (1) devenum.dll, (2) diactfrm.dll, (3) wmm2filt.dll, (4) fsusd.dll, (5) dmdskmgr.dll, (6) browsewm.dll, (7) browseui.dll, (8) shell32.dll, (9) mshtml.dll, (10) inetcfg.dll, (11) infosoft.dll, (12) query.dll, (13) syncui.dll, (14) clbcatex.dll, (15) clbcatq.dll, (16) comsvcs.dll, and (17) msconf.dll, which causes memory corruption, aka "COM Object Instantiation Memory Corruption Vulnerability," a different vulnerability than CVE-2005-2087.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-23T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-08-25T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:46:00.254-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:37.050-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:49.198-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:11.471-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criteria operator="OR" comment="the version of mshtml.dll is less than 6.0.2800.1515 or 6.0.2800.1516">
            <criterion comment="the version of mshtml.dll is less than 6.0.2800.1515 (RTMGDR)" negate="false" test_ref="oval:org.mitre.oval:tst:2418"/>
            <criterion comment="the version of mshtml.dll is less than 6.0.2800.1516 (RTMQFE)" negate="false" test_ref="oval:org.mitre.oval:tst:2417"/>
          </criteria>
          <criterion comment="the patch kb896727 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1129"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12346" version="3" class="vulnerability">
      <metadata>
        <title>Cross-site Scripting in Redirect Response message</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0075" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0075"/>
        <description>Cross-site scripting vulnerability for Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other web users via the error message used in a URL redirect (""302 Object Moved") message.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-16T12:00:00.000-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2011-01-12T13:28:46.784-05:00">DRAFT</status_change>
            <status_change date="2011-01-31T04:00:09.266-05:00">INTERIM</status_change>
            <status_change date="2011-02-21T04:00:24.742-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="vulnerable IIS 4.0 on Windows NT">
          <extend_definition comment="Microsoft Windows NT is installed" definition_ref="oval:org.mitre.oval:def:36"/>
          <extend_definition comment="Microsoft IIS 4.0 is installed" definition_ref="oval:org.mitre.oval:def:12482"/>
          <criterion comment="the version of w3svc.dll is less than 4.2.775.1" test_ref="oval:org.mitre.oval:tst:42232"/>
          <criterion comment="FTP Enabled" test_ref="oval:org.mitre.oval:tst:3074"/>
        </criteria>
        <criteria operator="AND" comment="vulnerable IIS 5.0 on Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft IIS 5.0 is installed" definition_ref="oval:org.mitre.oval:def:731"/>
          <criterion comment="the version of w3svc.dll is less than 5.0.2195.5269" test_ref="oval:org.mitre.oval:tst:42203"/>
          <criterion comment="FTP Enabled" test_ref="oval:org.mitre.oval:tst:3074"/>
        </criteria>
        <criteria operator="AND" comment="vulnerable IIS 5.1 on Windows XP">
          <extend_definition comment="Microsoft Windows XP is installed" definition_ref="oval:org.mitre.oval:def:105"/>
          <extend_definition comment="Microsoft IIS 5.1 is installed" definition_ref="oval:org.mitre.oval:def:460"/>
          <criterion comment="the version of w3svc.dll is less than 5.1.2600.41" test_ref="oval:org.mitre.oval:tst:41232"/>
          <criterion comment="FTP Enabled" test_ref="oval:org.mitre.oval:tst:3074"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12334" version="3" class="vulnerability">
      <metadata>
        <title>Vulnerability in the Standard PHP Library (SPL) extension in PHP before 5.3.4</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>PHP</product>
        </affected>
        <reference ref_id="CVE-2011-0754" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0754" source="CVE"/>
        <description>The SplFileInfo::getType function in the Standard PHP Library (SPL) extension in PHP before 5.3.4 on Windows does not properly detect symbolic links, which might make it easier for local users to conduct symlink attacks by leveraging cross-platform differences in the stat structure, related to lack of a FILE_ATTRIBUTE_REPARSE_POINT check.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-03-29T09:34:15-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-03-29T14:26:01.373-04:00">DRAFT</status_change>
            <status_change date="2011-04-18T04:00:16.652-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:00:33.804-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="PHP is installed" definition_ref="oval:org.mitre.oval:def:12410"/>
        <criterion comment="Check if the version of PHP is less than 5.3.4" test_ref="oval:org.mitre.oval:tst:41865"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12315" version="3" class="vulnerability">
      <metadata>
        <title>Access violation in URL error handling</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0072" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0072"/>
        <description>The w3svc.dll ISAPI filter in Front Page Server Extensions and ASP.NET for Internet Information Server (IIS) 4.0, 5.0, and 5.1 does not properly handle the error condition when a long URL is provided, which allows remote attackers to cause a denial of service (crash) when the URL parser accesses a null pointer.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-16T12:00:00.000-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2011-01-12T13:28:45.920-05:00">DRAFT</status_change>
            <status_change date="2011-01-31T04:00:07.873-05:00">INTERIM</status_change>
            <status_change date="2011-02-21T04:00:21.628-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="vulnerable IIS 4.0 on Windows NT">
          <extend_definition comment="Microsoft Windows NT is installed" definition_ref="oval:org.mitre.oval:def:36"/>
          <extend_definition comment="Microsoft IIS 4.0 is installed" definition_ref="oval:org.mitre.oval:def:12482"/>
          <criterion comment="the version of w3svc.dll is less than 4.2.775.1" test_ref="oval:org.mitre.oval:tst:42232"/>
          <criterion comment="FTP Enabled" test_ref="oval:org.mitre.oval:tst:3074"/>
        </criteria>
        <criteria operator="AND" comment="vulnerable IIS 5.0 on Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft IIS 5.0 is installed" definition_ref="oval:org.mitre.oval:def:731"/>
          <criterion comment="the version of w3svc.dll is less than 5.0.2195.5269" test_ref="oval:org.mitre.oval:tst:42203"/>
          <criterion comment="FTP Enabled" test_ref="oval:org.mitre.oval:tst:3074"/>
        </criteria>
        <criteria operator="AND" comment="vulnerable IIS 5.1 on Windows XP">
          <extend_definition comment="Microsoft Windows XP is installed" definition_ref="oval:org.mitre.oval:def:105"/>
          <extend_definition comment="Microsoft IIS 5.1 is installed" definition_ref="oval:org.mitre.oval:def:460"/>
          <criterion comment="the version of w3svc.dll is less than 5.1.2600.41" test_ref="oval:org.mitre.oval:tst:41232"/>
          <criterion comment="FTP Enabled" test_ref="oval:org.mitre.oval:tst:3074"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12307" version="4" class="vulnerability">
      <metadata>
        <title>Microsoft-discovered variant of Chunked Encoding buffer overrun</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0147" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0147"/>
        <description>Buffer overflow in the ASP data transfer mechanism in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to cause a denial of service or execute code, aka "Microsoft-discovered variant of Chunked Encoding buffer overrun."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-16T12:00:00.000-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2011-01-12T13:28:44.851-05:00">DRAFT</status_change>
            <status_change date="2011-01-31T04:00:07.524-05:00">INTERIM</status_change>
            <status_change date="2011-02-21T04:00:21.259-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="vulnerable IIS 4.0 on Windows NT">
          <extend_definition comment="Microsoft Windows NT is installed" definition_ref="oval:org.mitre.oval:def:36"/>
          <extend_definition comment="Microsoft IIS 4.0 is installed" definition_ref="oval:org.mitre.oval:def:12482"/>
          <criterion comment="the version of w3svc.dll is less than 4.2.775.1" test_ref="oval:org.mitre.oval:tst:42232"/>
          <criterion comment="FTP Enabled" test_ref="oval:org.mitre.oval:tst:3074"/>
        </criteria>
        <criteria operator="AND" comment="vulnerable IIS 5.0 on Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft IIS 5.0 is installed" definition_ref="oval:org.mitre.oval:def:731"/>
          <criterion comment="the version of w3svc.dll is less than 5.0.2195.5269" test_ref="oval:org.mitre.oval:tst:42203"/>
          <criterion comment="FTP Enabled" test_ref="oval:org.mitre.oval:tst:3074"/>
        </criteria>
        <criteria operator="AND" comment="vulnerable IIS 5.1 on Windows XP">
          <extend_definition comment="Microsoft Windows XP is installed" definition_ref="oval:org.mitre.oval:def:105"/>
          <extend_definition comment="Microsoft IIS 5.1 is installed" definition_ref="oval:org.mitre.oval:def:460"/>
          <criterion comment="the version of w3svc.dll is less than 5.1.2600.41" test_ref="oval:org.mitre.oval:tst:41232"/>
          <criterion comment="FTP Enabled" test_ref="oval:org.mitre.oval:tst:3074"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1230" version="6" class="vulnerability">
      <metadata>
        <title>Windows Media Player PNG Vulnerability (v7.1)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Media Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0025" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0025"/>
        <description>Stack-based buffer overflow in Microsoft Windows Media Player 9 and 10 allows remote attackers to execute arbitrary code via a PNG image with a large chunk size.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:15.443-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:04.887-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:952" date="2007-01-24T21:37:00.382-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-01-24T21:38:24.489-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:36.883-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:952 - def:5942 &amp; def:5689, Enhanced to cover WinVista, 2008, 2003 &amp; also 64-bit with service packs" date="2011-11-15T14:56:00.873-05:00">
              <contributor organization="SecPod Technologies">Pradeep R B</contributor>
            </modified>
            <status_change date="2011-11-15T14:58:49.961-05:00">INTERIM</status_change>
            <status_change date="2011-12-05T04:00:04.603-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:952 - Updated series of States to escape .(period) character." date="2012-01-13T17:30:00.463-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2012-01-13T17:34:55.886-05:00">INTERIM</status_change>
            <status_change date="2012-01-30T04:00:09.182-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Media Player 7.1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1066"/>
        <criterion comment="the version of wmpui.dll is less than 7.10.0.3076" negate="false" test_ref="oval:org.mitre.oval:tst:1065"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:123" version="5" class="vulnerability">
      <metadata>
        <title>IE Improper Object Tag Handling</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0809" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0809"/>
        <description>Internet Explorer 5.01 through 6.0 does not properly handle object tags returned from a Web server during XML data binding, which allows remote attackers to execute arbitrary code via an HTML e-mail message or web page.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T05:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2004-03-04T05:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </modified>
            <status_change date="2004-03-25T05:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="modified wrt-18 - Changed value element to include pattern match">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:45:58.068-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:36.692-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:43.349-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:11.283-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Internet Explorer 6.0 or IE 6.0 SP1 is installed">
            <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
            <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          </criteria>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1264" negate="false" test_ref="oval:org.mitre.oval:tst:2918"/>
          <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
            </criteria>
          </criteria>
          <criterion comment=".hta applications are enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2915"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1228" version="7" class="vulnerability">
      <metadata>
        <title>DNS RPC Management Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1748" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1748"/>
        <description>Stack-based buffer overflow in the RPC interface in the Domain Name System (DNS) Server Service in Microsoft Windows 2000 Server SP 4, Server 2003 SP 1, and Server 2003 SP 2 allows remote attackers to execute arbitrary code via a long zone name containing character constants represented by escape sequences.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-05-08T19:30:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-05-09T12:53:06-04:00">DRAFT</status_change>
            <status_change date="2007-05-31T15:26:32.439-04:00">INTERIM</status_change>
            <status_change date="2007-06-15T11:07:34.368-04:00">ACCEPTED</status_change>
            <modified comment="Multiple corrections and update to POSIX compatibility for ste:2656" date="2010-11-29T16:12:00.873-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-11-29T16:12:59.345-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:30.183-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1228 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:06:04.397-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:00:36.198-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="File version of DNS.exe" test_ref="oval:org.mitre.oval:tst:4125"/>
        </criteria>
        <criteria operator="AND" comment="Windows Server 2003 Service Pack 1 version">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="File version of DNS.exe" test_ref="oval:org.mitre.oval:tst:3163"/>
        </criteria>
        <criteria operator="AND" comment="Windows Server 2003 Service Pack 2 version">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <criterion comment="File version of DNS.exe" test_ref="oval:org.mitre.oval:tst:3758"/>
        </criteria>
        <criteria operator="AND" comment="Windows Server 2003 Service Pack 1 (64-bit) version">
          <extend_definition comment="Microsoft Windows Server 2003 is installed" definition_ref="oval:org.mitre.oval:def:128"/>
          <criterion comment="64-Bit (x64 architecture) version of Windows is installed" test_ref="oval:org.mitre.oval:tst:2744"/>
          <criterion comment="Win2K/XP/2003/Vista service pack 1 is installed" test_ref="oval:org.mitre.oval:tst:2843"/>
          <criterion comment="File version of DNS.exe" test_ref="oval:org.mitre.oval:tst:3163"/>
        </criteria>
        <criteria operator="AND" comment="Windows Server 2003 Service Pack 2 (64-bit) version">
          <extend_definition comment="Microsoft Windows Server 2003 is installed" definition_ref="oval:org.mitre.oval:def:128"/>
          <criterion comment="64-Bit (x64 architecture) version of Windows is installed" test_ref="oval:org.mitre.oval:tst:2744"/>
          <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" test_ref="oval:org.mitre.oval:tst:2837"/>
          <criterion comment="File version of DNS.exe" test_ref="oval:org.mitre.oval:tst:3758"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:128" version="7" class="inventory">
      <metadata>
        <title>Microsoft Windows Server 2003 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_2003_server"/>
        <description>The operating system installed on the system is Microsoft Windows Server
          2003.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-26T12:55:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2006-06-26T12:55:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added CPE reference." date="2007-04-30T07:48:00.775-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-30T08:05:37.807-04:00">INTERIM</status_change>
            <status_change date="2007-05-23T15:05:26.547-04:00">ACCEPTED</status_change>
            <modified comment="Changed the CPE reference" date="2008-04-04T11:17:00.348-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2008-04-04T11:26:22.372-04:00">INTERIM</status_change>
            <status_change date="2008-04-21T04:00:11.254-04:00">ACCEPTED</status_change>
            <modified comment="Changed the test for windows to be case insensitive and replaced the test for Windows 5.2 with a new test for 2003" date="2009-12-02T16:05:00.749-04:00">
              <contributor organization="National Institute of Standards and Technology">Tim
                Harrison</contributor>
            </modified>
            <status_change date="2009-12-02T16:05:00.749-04:00">INTERIM</status_change>
            <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:56:00.085-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim
                Harrison</contributor>
            </modified>
            <modified comment="Updating regex to include parenthesis" date="2009-12-08T17:31:00.354-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim
                Harrison</contributor>
            </modified>
            <status_change date="2009-12-28T04:00:06.591-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:128 - Updated CPE reference" date="2011-02-17T13:33:00.123-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2011-02-17T13:35:10.049-05:00">INTERIM</status_change>
            <status_change date="2011-03-07T04:00:10.940-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criterion comment="Windows Server 2003 is installed" test_ref="oval:org.mitre.oval:tst:11145"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12271" version="3" class="vulnerability">
      <metadata>
        <title>Race condition vulnerability in the PCNTL extension in PHP before 5.3.4</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>PHP</product>
        </affected>
        <reference ref_id="CVE-2011-0753" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0753" source="CVE"/>
        <description>Race condition in the PCNTL extension in PHP before 5.3.4, when a user-defined signal handler exists, might allow context-dependent attackers to cause a denial of service (memory corruption) via a large number of concurrent signals.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-03-29T09:34:17-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-03-29T14:26:01.891-04:00">DRAFT</status_change>
            <status_change date="2011-04-18T04:00:14.909-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:00:31.174-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="PHP is installed" definition_ref="oval:org.mitre.oval:def:12410"/>
        <criterion comment="Check if the version of PHP is less than 5.3.4" test_ref="oval:org.mitre.oval:tst:41865"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12242" version="3" class="vulnerability">
      <metadata>
        <title>Heap corruption in the Intel Indeo41 codec</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4313" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4313"/>
        <description>ir32_32.dll 3.24.15.3 in the Indeo32 codec in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to cause a denial of service (heap corruption) or execute arbitrary code via malformed data in a stream in a media file, as demonstrated by an AVI file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-09-14T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-11-10T17:01:32.105-05:00">DRAFT</status_change>
            <status_change date="2010-11-29T04:00:11.947-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:28.577-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4 or later">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Aclayers.dll is less than 5.0.2195.7358" test_ref="oval:org.mitre.oval:tst:40913"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="the version of Aclayers.dll is less than 5.1.2600.3647" test_ref="oval:org.mitre.oval:tst:41750"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of Aclayers.dll is less than 5.1.2600.5906" test_ref="oval:org.mitre.oval:tst:41843"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criteria operator="OR">
            <criterion comment="the version of Aclayers.dll is less than 5.2.3790.4624" test_ref="oval:org.mitre.oval:tst:41702"/>
            <criterion comment="the version of Waclayers.dll is less than 5.2.3790.4624" test_ref="oval:org.mitre.oval:tst:40983"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1224" version="2" class="vulnerability">
      <metadata>
        <title>Step-by-Step Interactive Training Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Interactive Training</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1212" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1212"/>
        <description>Buffer overflow in Microsoft Step-by-Step Interactive Training (orun32.exe) allows remote attackers to execute arbitrary code via a bookmark link file (.cbo, cbl, or .cbm extension) with a long User field.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-08T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2005-08-09T07:56:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-08-24T09:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1072 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-28T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:28:32.053-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Microsoft Interactive Training is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1073"/>
        <criterion comment="the version of Orun32.exe is less than 3.5.0.117" negate="false" test_ref="oval:org.mitre.oval:tst:1072"/>
        <criterion comment="the patch kb898458  is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1071"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1222" version="6" class="vulnerability">
      <metadata>
        <title>MSDTC Invalid Memory Access Vulnerability (Win2K)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0034" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0034"/>
        <description>Heap-based buffer overflow in the CRpcIoManagerServer::BuildContext function in msdtcprx.dll for Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0 and Windows 2000 SP2 and SP3 allows remote attackers to execute arbitrary code via a long fifth argument to the BuildContextW or BuildContext opcode, which triggers a bug in the NdrAllocate function, aka the MSDTC Invalid Memory Access Vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-10T03:16:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:15.295-04:00">ACCEPTED</status_change>
            <modified comment="Fixed regex in ste:2889.  Implemented by Matthew Wojcik." date="2007-03-06T18:19:00.507-05:00">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2007-03-06T18:21:15.023-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:16:46.195-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1222 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:06:19.719-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:00:35.773-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="the version of Msdtctm.dll is less than 2000.2.3535.0" test_ref="oval:org.mitre.oval:tst:1074"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12209" version="5" class="vulnerability">
      <metadata>
        <title>Untrusted search path vulnerability in Microsoft Windows Progman Group Converter</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows XP</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3139" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3139"/>
        <description>Untrusted search path vulnerability in Microsoft Windows Progman Group Converter (grpconv.exe) allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse imm.dll that is located in the same folder as a .grp file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-22T16:52:53">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-10-29T13:17:52.365-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:24.150-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:37.339-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:12209 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:05:06.384-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:00:27.181-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="grpconv.exe in Microsoft Windows XP SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Check if the version of grpconv.exe in Microsoft Windows XP SP3 is less than or equal to 5.1.2600.5512" test_ref="oval:org.mitre.oval:tst:41692"/>
        </criteria>
        <criteria operator="AND" comment="grpconv.exe in Microsoft Windows XP SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="Check if the version of grpconv.exe in Microsoft Windows XP SP2 is less than or equal to 5.1.2600.2180" test_ref="oval:org.mitre.oval:tst:41681"/>
        </criteria>
        <criteria operator="AND" comment="grpconv.exe in Microsoft Windows 2000 SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Check if the version of grpconv.exe in Microsoft Windows 2000 SP4 is less than or equal to 5.0.2134.1" test_ref="oval:org.mitre.oval:tst:41132"/>
        </criteria>
        <criteria operator="AND" comment="grpconv.exe in Microsoft Windows server 2003 SP2">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <criterion comment="Check if the version of grpconv.exe in Microsoft Windows server 2003 SP2 is less than or equal to 5.2.3790.3959" test_ref="oval:org.mitre.oval:tst:41470"/>
        </criteria>
        <criteria operator="AND" comment="grpconv.exe in Microsoft Windows Server 2003 SP1">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="Check if the version of grpconv.exe in Microsoft Windows Server 2003 SP1 is less than or equal to 5.2.3790.1830" test_ref="oval:org.mitre.oval:tst:41674"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12188" version="3" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in the Intel Indeo41 codec</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4309" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4309"/>
        <description>Heap-based buffer overflow in the Intel Indeo41 codec for Windows Media Player in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via a large size value in a movi record in an IV41 stream in a media file, as demonstrated by an AVI file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-09-14T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-11-10T17:01:30.803-05:00">DRAFT</status_change>
            <status_change date="2010-11-29T04:00:10.648-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:26.411-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4 or later">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Aclayers.dll is less than 5.0.2195.7358" test_ref="oval:org.mitre.oval:tst:40913"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="the version of Aclayers.dll is less than 5.1.2600.3647" test_ref="oval:org.mitre.oval:tst:41750"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of Aclayers.dll is less than 5.1.2600.5906" test_ref="oval:org.mitre.oval:tst:41843"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criteria operator="OR">
            <criterion comment="the version of Aclayers.dll is less than 5.2.3790.4624" test_ref="oval:org.mitre.oval:tst:41702"/>
            <criterion comment="the version of Waclayers.dll is less than 5.2.3790.4624" test_ref="oval:org.mitre.oval:tst:40983"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1213" version="6" class="vulnerability">
      <metadata>
        <title>Windows 2000 TAPI Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Telephony Service</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0058" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0058"/>
        <description>Buffer overflow in the Telephony Application Programming Interface (TAPI) for Microsoft Windows 98, Windows 98 SE, Windows ME, Windows 2000, Windows XP, and Windows Server 2003 allows attackers elevate privileges or execute arbitrary code via a crafted message.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-11T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected and tightened regular expression in ste:2610" date="2010-12-02T11:46:00.307-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-12-02T11:47:28.226-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:23.444-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:46:11.511-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:00:33.867-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows 2000 (sp4 or earlier) is installed">
            <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
            <criterion comment="Win2K/XP/2003 service pack 5 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2790"/>
          </criteria>
          <criterion comment="the version of tapisrv.dll is less than 5.0.2195.7057" negate="false" test_ref="oval:org.mitre.oval:tst:1075"/>
          <criterion comment="the patch kb893756 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:1192"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the Telephony service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:1191"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12124" version="3" class="vulnerability">
      <metadata>
        <title>Buffer Overrun in HTTP Header handling</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0150" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0150"/>
        <description>Buffer overflow in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to spoof the safety check for HTTP headers and cause a denial of service or execute arbitrary code via HTTP header field values.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-16T12:00:00.000-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2011-01-12T13:28:45.156-05:00">DRAFT</status_change>
            <status_change date="2011-01-31T04:00:05.280-05:00">INTERIM</status_change>
            <status_change date="2011-02-21T04:00:12.753-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="vulnerable IIS 4.0 on Windows NT">
          <extend_definition comment="Microsoft Windows NT is installed" definition_ref="oval:org.mitre.oval:def:36"/>
          <extend_definition comment="Microsoft IIS 4.0 is installed" definition_ref="oval:org.mitre.oval:def:12482"/>
          <criterion comment="the version of w3svc.dll is less than 4.2.775.1" test_ref="oval:org.mitre.oval:tst:42232"/>
          <criterion comment="FTP Enabled" test_ref="oval:org.mitre.oval:tst:3074"/>
        </criteria>
        <criteria operator="AND" comment="vulnerable IIS 5.0 on Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft IIS 5.0 is installed" definition_ref="oval:org.mitre.oval:def:731"/>
          <criterion comment="the version of w3svc.dll is less than 5.0.2195.5269" test_ref="oval:org.mitre.oval:tst:42203"/>
          <criterion comment="FTP Enabled" test_ref="oval:org.mitre.oval:tst:3074"/>
        </criteria>
        <criteria operator="AND" comment="vulnerable IIS 5.1 on Windows XP">
          <extend_definition comment="Microsoft Windows XP is installed" definition_ref="oval:org.mitre.oval:def:105"/>
          <extend_definition comment="Microsoft IIS 5.1 is installed" definition_ref="oval:org.mitre.oval:def:460"/>
          <criterion comment="the version of w3svc.dll is less than 5.1.2600.41" test_ref="oval:org.mitre.oval:tst:41232"/>
          <criterion comment="FTP Enabled" test_ref="oval:org.mitre.oval:tst:3074"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:121" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft SQL Server Extended Stored Procedure Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft SQL Server 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0154" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0154"/>
        <description>Buffer overflows in extended stored procedures for Microsoft SQL Server 7.0 and 2000 allow remote attackers to cause a denial of service or execute arbitrary code via a database query with certain long arguments.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
            </submitted>
            <modified date="2005-04-08T10:31:00.000-04:00" comment="modified wft-237 - literal string corrected">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:31:00.000-04:00" comment="modified wft-236 - corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:31:00.000-04:00" comment="modified wft-65 - Corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:31:00.000-04:00" comment="modified wft-66 - corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:31:00.000-04:00" comment="modified wft-67 - Corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:32:00.000-04:00" comment="modified wft-68 - Corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:33:00.000-04:00" comment="modified wft-69 - corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-11T08:48:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:121 - SQL Server 2000 has been replaced by Microsoft SQL Server 2000" date="2014-06-02T14:59:00.848-04:00">
              <contributor organization="McAfee, Inc.">Jerome Athias</contributor>
            </modified>
            <status_change date="2014-06-02T15:00:55.121-04:00">INTERIM</status_change>
            <status_change date="2014-06-23T04:00:23.692-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="SQL Server 2000 is installed" test_ref="oval:org.mitre.oval:tst:2977"/>
        <criterion comment="the version of sqlservr.exe is less than 2000.80.608.0" test_ref="oval:org.mitre.oval:tst:2926"/>
        <criterion comment="the version of odsole70.dll is less than 2000.80.606.0" test_ref="oval:org.mitre.oval:tst:2925"/>
        <criterion comment="the version of xpqueue.dll is less than 2000.80.606.0" test_ref="oval:org.mitre.oval:tst:2924"/>
        <criterion comment="the version of xprepl.dll is less than 2000.80.606.0" test_ref="oval:org.mitre.oval:tst:2923"/>
        <criterion comment="the version of xplog70.dll is less than 2000.80.606.0" test_ref="oval:org.mitre.oval:tst:2922"/>
        <criterion comment="the version of xpweb70.dll is less than 2000.80.606.0" test_ref="oval:org.mitre.oval:tst:2921"/>
        <criterion comment="the version of xpstar.dll is less than 2000.80.628.0" test_ref="oval:org.mitre.oval:tst:2920"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1207" version="4" class="vulnerability">
      <metadata>
        <title>IE6,SP1 File Disclosure via Redirects Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0648" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0648"/>
        <description>The legacy &lt;script> data-island capability for XML in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to read arbitrary XML files, and portions of other files, via a URL whose "src" attribute redirects to a local file.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-22T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-06-22T12:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:46:06.502-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:35.449-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:51.802-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:10.519-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criteria operator="OR" comment="the version of mshtml.dll is less than 6.0.2800.1505 or 6.0.2800.1506">
            <criterion comment="the version of mshtml.dll is less than 6.0.2800.1505 (RTMGDR)" negate="false" test_ref="oval:org.mitre.oval:tst:2365"/>
            <criterion comment="the version of mshtml.dll is less than 6.0.2800.1506 (RTMQFE)" negate="false" test_ref="oval:org.mitre.oval:tst:2364"/>
          </criteria>
          <criterion comment="the patch kb883939 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2750"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12016" version="3" class="vulnerability">
      <metadata>
        <title>Security bypass vulnerability in the extract function in PHP before 5.2.15</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>PHP</product>
        </affected>
        <reference ref_id="CVE-2011-0752" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0752" source="CVE"/>
        <description>The extract function in PHP before 5.2.15 does not prevent use of the EXTR_OVERWRITE parameter to overwrite (1) the GLOBALS superglobal array and (2) the this variable, which allows context-dependent attackers to bypass intended access restrictions by modifying data structures that were not intended to depend on external input, a related issue to CVE-2005-2691 and CVE-2006-3758.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-03-29T09:34:16-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-03-29T14:26:01.666-04:00">DRAFT</status_change>
            <status_change date="2011-04-18T04:00:07.338-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:00:19.425-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="PHP is installed" definition_ref="oval:org.mitre.oval:def:12410"/>
        <criterion comment="Check if the version of PHP is less than 5.2.15" test_ref="oval:org.mitre.oval:tst:42097"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12008" version="3" class="vulnerability">
      <metadata>
        <title>Cross-site Scripting in HTTP Error Page</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0148" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0148"/>
        <description>Cross-site scripting vulnerability in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other users via an HTTP error page.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-16T12:00:00.000-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2011-01-12T13:28:46.500-05:00">DRAFT</status_change>
            <status_change date="2011-01-31T04:00:04.551-05:00">INTERIM</status_change>
            <status_change date="2011-02-21T04:00:09.425-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="vulnerable IIS 4.0 on Windows NT">
          <extend_definition comment="Microsoft Windows NT is installed" definition_ref="oval:org.mitre.oval:def:36"/>
          <extend_definition comment="Microsoft IIS 4.0 is installed" definition_ref="oval:org.mitre.oval:def:12482"/>
          <criterion comment="the version of w3svc.dll is less than 4.2.775.1" test_ref="oval:org.mitre.oval:tst:42232"/>
          <criterion comment="FTP Enabled" test_ref="oval:org.mitre.oval:tst:3074"/>
        </criteria>
        <criteria operator="AND" comment="vulnerable IIS 5.0 on Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft IIS 5.0 is installed" definition_ref="oval:org.mitre.oval:def:731"/>
          <criterion comment="the version of w3svc.dll is less than 5.0.2195.5269" test_ref="oval:org.mitre.oval:tst:42203"/>
          <criterion comment="FTP Enabled" test_ref="oval:org.mitre.oval:tst:3074"/>
        </criteria>
        <criteria operator="AND" comment="vulnerable IIS 5.1 on Windows XP">
          <extend_definition comment="Microsoft Windows XP is installed" definition_ref="oval:org.mitre.oval:def:105"/>
          <extend_definition comment="Microsoft IIS 5.1 is installed" definition_ref="oval:org.mitre.oval:def:460"/>
          <criterion comment="the version of w3svc.dll is less than 5.1.2600.41" test_ref="oval:org.mitre.oval:tst:41232"/>
          <criterion comment="FTP Enabled" test_ref="oval:org.mitre.oval:tst:3074"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:731" version="4" class="inventory">
      <metadata>
        <title>Microsoft IIS 5.0 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft IIS 5.0</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:iis:5.0"/>
        <description>The application Microsoft IIS 5.0 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-27T12:29:36.527-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:48.090-04:00">ACCEPTED</status_change>
            <modified comment="Added CPE reference." date="2007-04-30T07:48:00.109-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-30T08:15:30.166-04:00">INTERIM</status_change>
            <status_change date="2007-05-23T15:05:51.847-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:731 - product info corrected" date="2015-04-15T12:33:00.646-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-04-15T12:36:19.664-04:00">INTERIM</status_change>
            <status_change date="2015-05-04T04:00:21.657-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="IIS major version equals 5" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS Minor Version equals 0" test_ref="oval:org.mitre.oval:tst:164"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:460" version="4" class="inventory">
      <metadata>
        <title>Microsoft IIS 5.1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft IIS 5.1</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:iis:5.1"/>
        <description>The application Microsoft IIS 5.1 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-27T12:29:27.089-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:41.067-04:00">ACCEPTED</status_change>
            <modified comment="Added CPE reference." date="2007-04-30T07:48:00.815-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-30T08:14:32.837-04:00">INTERIM</status_change>
            <status_change date="2007-05-23T15:05:46.398-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:460 - product info corrected" date="2015-04-15T12:33:00.646-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-04-15T12:36:19.071-04:00">INTERIM</status_change>
            <status_change date="2015-05-04T04:00:19.882-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="IIS major version equals 5" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS 5.1 Minor Version" test_ref="oval:org.mitre.oval:tst:1357"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12482" version="5" class="inventory">
      <metadata>
        <title>Microsoft IIS 4.0 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Microsoft IIS 4.0</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:iis:4.0"/>
        <description>The application Microsoft IIS 4.0 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-06-08T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2011-01-12T13:28:42.364-05:00">DRAFT</status_change>
            <status_change date="2011-01-31T04:00:12.477-05:00">INTERIM</status_change>
            <status_change date="2011-02-21T04:00:37.262-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:12482 - product info corrected" date="2015-04-15T12:33:00.646-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-04-15T12:36:18.911-04:00">INTERIM</status_change>
            <status_change date="2015-05-04T04:00:07.462-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="IIS 4.0 Major Version" test_ref="oval:org.mitre.oval:tst:3099"/>
        <criterion comment="IIS minor version equals 0" test_ref="oval:org.mitre.oval:tst:3098"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12" version="3" class="vulnerability">
      <metadata>
        <title>IE v5.5,SP2 Forced Script Execution</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0026" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0026"/>
        <description>Internet Explorer 5.5 and 6.0 allows remote attackers to bypass restrictions for executing scripts via an object that processes asynchronous events after the initial security checks have been made.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:44.205-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:10.389-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
        <criterion comment="the version of mshtml.dll is less than 5.50.4913.1100" negate="false" test_ref="oval:org.mitre.oval:tst:3122"/>
        <criterion comment="the patch q316059 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3121"/>
        <criterion comment="the patch q319282 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3120"/>
        <criterion comment="the patch q321232 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3119"/>
        <criterion comment="the patch q323759 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3118"/>
        <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
        <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
        <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11975" version="3" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the Indeo (CVE-2009-4311)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4311" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4311"/>
        <description>Unspecified vulnerability in the Indeo codec in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via crafted media content, as reported to Microsoft by Paul Byrne of NGS Software.  NOTE: this might overlap CVE-2008-3615.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-09-14T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-11-10T17:01:31.434-05:00">DRAFT</status_change>
            <status_change date="2010-11-29T04:00:07.940-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:20.557-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4 or later">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Aclayers.dll is less than 5.0.2195.7358" test_ref="oval:org.mitre.oval:tst:40913"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="the version of Aclayers.dll is less than 5.1.2600.3647" test_ref="oval:org.mitre.oval:tst:41750"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of Aclayers.dll is less than 5.1.2600.5906" test_ref="oval:org.mitre.oval:tst:41843"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criteria operator="OR">
            <criterion comment="the version of Aclayers.dll is less than 5.2.3790.4624" test_ref="oval:org.mitre.oval:tst:41702"/>
            <criterion comment="the version of Waclayers.dll is less than 5.2.3790.4624" test_ref="oval:org.mitre.oval:tst:40983"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1197" version="3" class="vulnerability">
      <metadata>
        <title>Firefox/Mozilla Suite Chrome Window Spoofing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2707" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2707"/>
        <description>Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to spawn windows without user interface components such as the address and status bar, which could be used to conduct spoofing or phishing attacks.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-11T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-12T10:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:2367" date="2007-02-26T08:32:00.241-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-26T08:32:39.928-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:2370" date="2007-03-06T07:46:00.064-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:45.364-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:1444" date="2007-04-23T12:05:00.911-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:19:59.493-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:1445" date="2007-04-23T12:05:00.720-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:10:52.378-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Suite version 1.7.10 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.10 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2535"/>
          <criterion comment="Mozilla Suite version 1.7.10 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2534"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.6 or earlier is installed">
          <criterion comment="Firefox version 1.0.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2533"/>
          <criterion comment="Mozilla Firefox version 1.0.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2532"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1196" version="4" class="vulnerability">
      <metadata>
        <title>URL Parsing Memory Corruption Vulnerability (IE5.01,SP3)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0554" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0554"/>
        <description>Buffer overflow in the URL processor of Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a URL with a long hostname, aka "URL Parsing Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-05-11T05:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2824. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:48:00.494-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:52:28.261-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:35.079-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:49.394-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:10.022-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3015"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3539.2400" negate="false" test_ref="oval:org.mitre.oval:tst:1083"/>
          <criterion comment="the patch kb890923  is installed (Win2K SP3  Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:1082"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11947" version="3" class="vulnerability">
      <metadata>
        <title>MSO Large SPID Read AV Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Office XP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3336" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3336"/>
        <description>Microsoft Office XP SP3, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption, aka "MSO Large SPID Read AV Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-09T13:00:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </submitted>
            <status_change date="2010-11-12T11:25:34.833-05:00">DRAFT</status_change>
            <status_change date="2010-11-29T04:00:07.613-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:19.612-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Office XP is installed" definition_ref="oval:org.mitre.oval:def:663"/>
        <criterion comment="Mso.dll version is less than 10.0.6867.0" test_ref="oval:org.mitre.oval:tst:41798"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:663" version="11" class="inventory">
      <metadata>
        <title>Microsoft Office XP is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:office:xp"/>
        <description>The application Microsoft Office XP is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-07T09:15:51.244-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:58.628-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:1339" date="2007-04-23T12:05:00.247-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:26:29.609-04:00">INTERIM</status_change>
            <modified comment="Added CPE reference." date="2007-04-30T07:48:00.390-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-23T15:05:49.843-04:00">ACCEPTED</status_change>
            <modified comment="Now detects the non-OEM versions of Office XP." date="2008-11-10T10:51:00.927-05:00">
              <contributor organization="Secure Elements, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2008-11-10T10:57:34.946-05:00">INTERIM</status_change>
            <status_change date="2008-12-01T04:00:19.113-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:2179 - Fixed some regular expressions to conform to the Authoring style guide." date="2011-10-03T15:44:00.952-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-10-03T15:45:21.258-04:00">INTERIM</status_change>
            <status_change date="2011-10-24T04:00:27.403-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:1339 - Fixed several false positives by setting negate = true.  Also fixed several style issues." date="2011-12-28T21:13:00.551-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2011-12-28T21:21:41.130-05:00">INTERIM</status_change>
            <status_change date="2012-01-16T04:03:18.840-05:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:58.775-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:58.775-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:17.314-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:4586 - modified comments" date="2014-02-28T15:13:00.247-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-28T15:16:15.050-05:00">INTERIM</status_change>
            <status_change date="2014-03-17T04:00:30.146-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Microsoft Office XP OEM is installed" test_ref="oval:org.mitre.oval:tst:2327"/>
        <criterion comment="Microsoft Office XP is installed" test_ref="oval:org.mitre.oval:tst:9294"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11939" version="4" class="vulnerability">
      <metadata>
        <title>Stack-based buffer overflow in the GD extension in PHP before 5.2.15 and 5.3.x before 5.3.4</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>PHP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-4698" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4698"/>
        <description>Stack-based buffer overflow in the GD extension in PHP before 5.2.15 and 5.3.x before 5.3.4 allows context-dependent attackers to cause a denial of service (application crash) via a large number of anti-aliasing steps in an argument to the imagepstext function.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-03-22T16:21:49">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-03-22T13:47:56.600-04:00">DRAFT</status_change>
            <status_change date="2011-04-11T04:00:03.928-04:00">INTERIM</status_change>
            <status_change date="2011-05-02T04:00:05.128-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="PHP is installed" definition_ref="oval:org.mitre.oval:def:12410"/>
        <criterion comment="Check if the version of PHP is less than 5.2.15 or 5.3.x before 5.3.4" test_ref="oval:org.mitre.oval:tst:42457"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12410" version="4" class="inventory">
      <metadata>
        <title>PHP is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>PHP</product>
        </affected>
        <reference ref_id="cpe:/a:php:php" source="CPE"/>
        <description>PHP is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2010-12-23T15:27:18">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-12-27T20:21:09.434-05:00">DRAFT</status_change>
            <status_change date="2011-01-17T04:00:16.671-05:00">INTERIM</status_change>
            <modified comment="Added a registry test to support for lower versions of PHP" date="2011-02-08T16:21:49.575+05:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </modified>
            <status_change date="2011-04-04T04:00:17.011-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Check if PHP is installed" test_ref="oval:org.mitre.oval:tst:41246"/>
        <criterion comment="Check if PHP lower versions are installed" test_ref="oval:org.mitre.oval:tst:42177"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1192" version="6" class="vulnerability">
      <metadata>
        <title>.lnk File-Properties Remote Code Execution Vulnerability (Windows 2000)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2118" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2118"/>
        <description>Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote user-assisted attackers to execute arbitrary commands via a crafted shortcut (.lnk) file with long font properties that lead to a buffer overflow when the user views the file's properties using Windows Explorer, a different vulnerability than CVE-2005-2122.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-31T12:00:00.000-04:00" comment="removed an incorrect leading ^ from the value entity of ste:2402">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-31T00:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:15.115-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1192 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:05:47.594-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:00:30.541-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Windows 2000 is installed" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="Win2K/XP/2003 service pack 4 is installed" test_ref="oval:org.mitre.oval:tst:2569"/>
        <criterion comment="shell32.dll is less than 5.0.3900.7071" test_ref="oval:org.mitre.oval:tst:1086"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1191" version="6" class="vulnerability">
      <metadata>
        <title>Win2K COM object Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0012" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0012"/>
        <description>Unspecified vulnerability in Windows Explorer in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via attack vectors involving COM objects and "crafted files and directories," aka the "Windows Shell Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed regex in ste:2889.  Implemented by Matthew Wojcik." date="2007-03-06T18:19:00.507-05:00">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2007-03-06T18:21:05.834-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:16:45.156-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1191 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:06:20.223-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:00:30.217-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="the version of shell32.dll is less than 5.0.3900.7078" test_ref="oval:org.mitre.oval:tst:1087"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11838" version="4" class="vulnerability" deprecated="true">
      <metadata>
        <title>DEPRECATED: Use-after-free vulnerability in the ReleaseInterface function in MSHTML.DLL in Microsoft Internet Explorer 8.0.7600.16385</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2011-0346" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0346"/>
        <description>Use-after-free vulnerability in the ReleaseInterface function in MSHTML.DLL in Microsoft Internet Explorer 8.0.7600.16385 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to the DOM implementation and the BreakAASpecial and BreakCircularMemoryReferences functions, as demonstrated by cross_fuzz, involving circular memory references.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-03-18T13:10:08">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-03-18T16:57:55.813-04:00">DRAFT</status_change>
            <status_change date="2011-04-04T04:00:05.750-04:00">INTERIM</status_change>
            <modified comment="Deprecated due to April 2011 Patch Tuesday" date="2011-04-18T00:26:44.052-04:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2011-04-18T00:26:44.052-04:00">DEPRECATED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
        <criterion comment="Check if Microsoft Internet Explorer version is equal to 8.0.7600.16385" test_ref="oval:org.mitre.oval:tst:42050"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:118" version="5" class="vulnerability">
      <metadata>
        <title>Windows 2000 SMB Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>SMB (Server Message Block)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0345" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0345"/>
        <description>Buffer overflow in the SMB capability for Microsoft Windows XP, 2000, and NT allows remote attackers to cause a denial of service and possibly execute arbitrary code via an SMB packet that specifies a smaller buffer length than is required.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-08T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed regex in ste:2889.  Implemented by Matthew Wojcik." date="2007-03-06T18:19:00.507-05:00">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2007-03-06T18:21:10.300-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:16:43.972-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:13.698-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:00:28.046-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 (sp3 or earlier) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="File %windir%\system32\Drivers\SRV.SYS is less than 5.0.2195.6699" negate="false" test_ref="oval:org.mitre.oval:tst:2933"/>
        <criterion comment="Patch Windows2000-KB817606-x86-ENU.exe Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2932"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11787" version="3" class="vulnerability">
      <metadata>
        <title>SChannel Malformed Certificate Request Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2566" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2566"/>
        <description>The Secure Channel (aka SChannel) security package in Microsoft Windows XP SP2 and SP3, and Windows Server 2003 SP2, does not properly validate certificate request messages from TLS and SSL servers, which allows remote servers to execute arbitrary code via a crafted SSL response, aka "SChannel Malformed Certificate Request Remote Code Execution Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-08-10T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-08-16T12:27:13.779-04:00">DRAFT</status_change>
            <status_change date="2010-09-06T04:11:27.755-04:00">INTERIM</status_change>
            <status_change date="2010-09-27T04:00:12.130-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP SP3 x86">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of schannel.dll is less than 5.1.2600.6006" test_ref="oval:org.mitre.oval:tst:40676"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP SP2 x64, Windows Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="the version of schannel.dll is less than 5.2.3790.4724" test_ref="oval:org.mitre.oval:tst:41575"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11730" version="5" class="vulnerability">
      <metadata>
        <title>Msxml2.XMLHTTP.3.0 Response Handling Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2561" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2561"/>
        <description>Microsoft XML Core Services (aka MSXML) 3.0 does not properly handle HTTP responses, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted response, aka "Msxml2.XMLHTTP.3.0 Response Handling Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-08-10T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-08-16T12:27:32.846-04:00">DRAFT</status_change>
            <status_change date="2010-09-06T04:11:19.769-04:00">INTERIM</status_change>
            <status_change date="2010-09-27T04:00:10.621-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:54.118-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:54.118-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:00:15.826-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft XML Core Services 3 is installed" definition_ref="oval:org.mitre.oval:def:415"/>
        <criteria operator="OR">
          <criteria operator="AND" comment="Vulnerable Microsoft Windows XP SP3 x86">
            <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
            <criterion comment="msxml3.dll version is less than 8.100.1052.0" test_ref="oval:org.mitre.oval:tst:41023"/>
          </criteria>
          <criteria operator="AND" comment="Vulnerable Microsoft Windows XP SP2 x64, Windows Server 2003 x86/x64/ia64 SP2">
            <criteria operator="OR">
              <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
              <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
              <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
              <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
            </criteria>
            <criterion comment="msxml3.dll version is less than 8.100.1051.0" test_ref="oval:org.mitre.oval:tst:40862"/>
          </criteria>
          <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 SP1, Server 2008 x86/x64/ia64">
            <criteria operator="OR">
              <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
              <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
              <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
              <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            </criteria>
            <criterion comment="msxml3.dll version is less than 8.100.4002.0" test_ref="oval:org.mitre.oval:tst:41397"/>
          </criteria>
          <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86/x64 SP2, Server 2008 x86/x64/ia64 SP2">
            <criteria operator="OR">
              <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
              <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
              <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
              <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
              <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
            </criteria>
            <criterion comment="msxml3.dll version is less than 8.100.5003.0" test_ref="oval:org.mitre.oval:tst:41662"/>
          </criteria>
          <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Windows Server 2008 R2 x64/ia64">
            <criteria operator="OR">
              <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
              <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            </criteria>
            <criteria operator="OR" comment="GDR or LDR Service branch">
              <criterion comment="msxml3.dll version is less than 8.110.7600.16605" test_ref="oval:org.mitre.oval:tst:41499"/>
              <criteria operator="AND" comment="LDR">
                <criterion comment="msxml3.dll version is greater than or equal to 8.110.7600.20000" test_ref="oval:org.mitre.oval:tst:41341"/>
                <criterion comment="msxml3.dll version is less than 8.110.7600.20728" test_ref="oval:org.mitre.oval:tst:41588"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:415" version="3" class="inventory">
      <metadata>
        <title>Microsoft XML Core Services 3 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft XML Core Services 3</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:xml_core_services:3"/>
        <description>Microsoft XML Core Services 3 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-10-11T05:29:41">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-13T14:55:00.00-04:00">DRAFT</status_change>
            <status_change date="2006-10-31T19:35:39.106-05:00">INTERIM</status_change>
            <status_change date="2006-11-21T21:27:48.903-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:415 - products added to inventories" date="2015-04-17T09:39:00.289-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-04-17T09:41:23.535-04:00">INTERIM</status_change>
            <status_change date="2015-05-04T04:00:19.498-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Microsoft XML Core Services 3 is installed." test_ref="oval:org.mitre.oval:tst:179"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:117" version="4" class="vulnerability">
      <metadata>
        <title>Microsoft ISA Server Cross-Site Scripting</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Security and Acceleration Server 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0526" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0526"/>
        <description>Cross-site scripting (XSS) vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to inject arbitrary web script via a URL containing the script in the domain name portion, which is not properly cleansed in the default error pages (1) 500.htm for "500 Internal Server error" or (2) 404.htm for "404 Not Found."</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.657-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-10-25T16:50:13.833-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:00:57.765-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:117 - Corrected capitalization and extra spacing errors in product names" date="2011-04-08T16:13:00.153-04:00">
              <contributor organization="AIST">Akihito Nakamura</contributor>
            </modified>
            <status_change date="2011-04-08T16:17:44.043-04:00">INTERIM</status_change>
            <status_change date="2011-04-25T04:00:04.930-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="ISA Server 2000 is installed" test_ref="oval:org.mitre.oval:tst:2935"/>
        <criterion negate="true" comment="ISA2000-KB816456-x86.exe" test_ref="oval:org.mitre.oval:tst:2934"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11677" version="3" class="vulnerability">
      <metadata>
        <title>Denial of service (memory corruption) in Microsoft Indeo codec</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4210" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4210"/>
        <description>The Indeo codec in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted media content.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-09-14T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-11-10T17:01:30.500-05:00">DRAFT</status_change>
            <status_change date="2010-11-29T04:00:05.322-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:14.406-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4 or later">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Aclayers.dll is less than 5.0.2195.7358" test_ref="oval:org.mitre.oval:tst:40913"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="the version of Aclayers.dll is less than 5.1.2600.3647" test_ref="oval:org.mitre.oval:tst:41750"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of Aclayers.dll is less than 5.1.2600.5906" test_ref="oval:org.mitre.oval:tst:41843"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criteria operator="OR">
            <criterion comment="the version of Aclayers.dll is less than 5.2.3790.4624" test_ref="oval:org.mitre.oval:tst:41702"/>
            <criterion comment="the version of Waclayers.dll is less than 5.2.3790.4624" test_ref="oval:org.mitre.oval:tst:40983"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11606" version="5" class="vulnerability">
      <metadata>
        <title>Pointer leakage vulnerability in Internet Explorer</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3886" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3886"/>
        <description>The CTimeoutEventList::InsertIntoTimeoutList function in Microsoft mshtml.dll uses a certain pointer value as part of producing Timer ID values for the setTimeout and setInterval methods in VBScript and JScript, which allows remote attackers to obtain sensitive information about the heap memory addresses used by an application, as demonstrated by the Internet Explorer 8 application.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-28T17:14:22">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-10-29T13:17:38.106-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:04.551-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:06.329-05:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:23:45.103-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:23:45.103-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:00:10.097-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Internet Explorer 6 on XP x86 SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Check if the version of mshtml.dll is less than or equal to 6.0.2900.6003" test_ref="oval:org.mitre.oval:tst:41596"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 6 on XP x64 SP2, Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR" comment="XP x64 Edition SP2 or Server 2003 SP2 (x86) or Server 2003 SP2 (x64) or Server 2003 (ia64) SP2">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Check if the version of mshtml.dll is less than or equal to 6.0.3790.4732" test_ref="oval:org.mitre.oval:tst:41762"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on XP x86/x64 SP3">
          <criteria operator="OR" comment=" XP (x86) SP3 or XP x64 Edition SP2">
            <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Check if the version of mshtml.dll is less than or equal to 7.0.6000.17080" test_ref="oval:org.mitre.oval:tst:41634"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64 SP1, Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista (32-bit) SP1 or Vista x64 Edition SP1 or Server 2008 (32-bit) or Server 2008 (64-bit) or Server 2008 (ia-64)">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Check if the version of mshtml.dll is less than or equal to 7.0.6001.18498" test_ref="oval:org.mitre.oval:tst:41538"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 7 on Vista x86/x64 SP2, Server 2008 x86/x64/ia64 SP2">
          <criteria operator="OR" comment="Vista (32-bit) SP2 or Vista x64 Edition SP2 or Server 2008 (32-bit) SP2 or Server 2008 x64 Edition SP2 or Server 2008 Itanium-Based Edition SP2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="Check if the version of mshtml.dll is less than or equal to 7.0.6002.18278" test_ref="oval:org.mitre.oval:tst:41024"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on XP x64 SP2,XP x86 SP3, Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR" comment="XP (x86) SP3 or XP x64 Edition SP2 or Server 2003 SP2 (x86) or Server 2003 SP2 (x64)">
            <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Check if the version of mshtml.dll is less than or equal to 8.0.6001.18939" test_ref="oval:org.mitre.oval:tst:40915"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on all Vista x86/x64, all Server 2008 x86/x64/ia64">
          <criteria operator="OR" comment="Vista (32-bit) SP1 or Vista x64 Edition SP1 or Vista (32-bit) SP2 or Vista x64 Edition SP2 or Server 2008 (32-bit) or Server 2008 (64-bit) or Server 2008 (32-bit) SP2 or Server 2008 x64 Edition SP2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:5254"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Check if the version of mshtml.dll is less than or equal to 8.0.6001.18943" test_ref="oval:org.mitre.oval:tst:41181"/>
        </criteria>
        <criteria operator="AND" comment="Internet Explorer 8 on Windows 7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="Windows 7 (32-bit) or x64 Edition or Server 2008 R2 x64 Edition or Server 2008 R2 Itanium-Based Edition">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criterion comment="Check if the version of mshtml.dll is less than or equal to 8.0.7600.16625" test_ref="oval:org.mitre.oval:tst:40975"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6438" version="9" class="inventory">
      <metadata>
        <title>Microsoft Windows Server 2008 R2 x64 Edition is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_server_2008:r2::x64"/>
        <description>The operating system installed on the system is Microsoft Windows Server 2008
          R2 x64 Edition</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-13T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-10-22T17:36:49.340-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:59.900-05:00">INTERIM</status_change>
            <modified comment="Changed registry check for amd64 to be case insensitive equals" date="2009-11-19T18:33:00.593-05:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </modified>
            <modified comment="Changed the test for 2008 R2 and windows to be case insensitive" date="2009-12-02T16:05:00.749-04:00">
              <contributor organization="National Institute of Standards and Technology">Tim
                Harrison</contributor>
            </modified>
            <status_change date="2009-12-02T16:05:00.749-04:00">INTERIM</status_change>
            <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:56:00.439-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim
                Harrison</contributor>
            </modified>
            <modified comment="Updating regex to include parenthesis" date="2009-12-08T17:32:00.144-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim
                Harrison</contributor>
            </modified>
            <status_change date="2010-01-04T04:01:47.909-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6438 - Corrected the CPE names for Windows Server 2008" date="2010-12-21T10:57:00.617-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2010-12-21T11:00:19.788-05:00">INTERIM</status_change>
            <status_change date="2011-02-07T04:00:14.887-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6438 - Modifications vary from minor OVAL title/description changes to suggesting an alternative CPE name to use." date="2011-09-28T11:29:00.976-04:00">
              <contributor organization="The MITRE Corporation">David Rothenberg</contributor>
            </modified>
            <status_change date="2011-09-28T11:33:40.706-04:00">INTERIM</status_change>
            <status_change date="2011-10-17T04:00:23.369-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:09.822-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:09.822-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:13.891-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:3180 - new inventory for SQL Server 2008 R2 64-bit" date="2013-07-05T09:33:00.078-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-05T09:37:49.762-04:00">INTERIM</status_change>
            <status_change date="2013-07-22T04:03:10.657-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criterion comment="Windows Server 2008 R2 is installed" test_ref="oval:org.mitre.oval:tst:10317"/>
        <criterion comment="a version of Windows for the x64 architecture is installed" test_ref="oval:org.mitre.oval:tst:3653"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6216" version="11" class="inventory">
      <metadata>
        <title>Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_server_2008::sp2:x64"/>
        <description>The operating system installed on the system is Microsoft Windows Server 2008 x64 Edition Service Pack 2</description>
        <oval_repository>
          <dates>
            <submitted date="2009-05-04T16:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-05-07T11:17:37.293-04:00">DRAFT</status_change>
            <status_change date="2009-05-25T04:02:07.677-04:00">INTERIM</status_change>
            <status_change date="2009-06-22T04:00:31.225-04:00">ACCEPTED</status_change>
            <modified comment="Changed registry check for amd64 to be a case insensitive equals" date="2009-09-04T10:48:00.140-05:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2009-09-07T04:00:28.404-04:00">INTERIM</status_change>
            <status_change date="2009-09-28T04:00:16.986-04:00">ACCEPTED</status_change>
            <modified comment="Changed registry check for amd64 to be case insensitive equals" date="2009-11-19T18:33:00.593-05:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2009-11-19T18:35:08.857-05:00">INTERIM</status_change>
            <modified comment="Changed the tests for SP2 and windows to be case insensitive" date="2009-12-02T16:05:00.749-04:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:54:00.233-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <status_change date="2009-12-21T04:00:49.331-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6216 - Corrected the CPE names for Windows Server 2008" date="2010-12-21T10:57:00.617-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2010-12-21T11:00:20.808-05:00">INTERIM</status_change>
            <status_change date="2011-02-07T04:00:14.501-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:44:24.321-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:03:17.572-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:3180 - new inventory for SQL Server 2008 R2 64-bit" date="2013-07-05T09:33:00.078-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-05T09:37:48.609-04:00">INTERIM</status_change>
            <status_change date="2013-07-22T04:03:09.474-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criterion comment="Windows Server 2008 is installed" test_ref="oval:org.mitre.oval:tst:7697"/>
        <criterion comment="a version of Windows for the x64 architecture is installed" test_ref="oval:org.mitre.oval:tst:3653"/>
        <criterion comment="Win2K/XP/2003/Vista/2008 service pack 2 is installed" test_ref="oval:org.mitre.oval:tst:3019"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6210" version="7" class="inventory">
      <metadata>
        <title>Microsoft Internet Explorer 8 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:ie:8"/>
        <description>A version of Microsoft Internet Explorer 8 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-03-23T10:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-03-23T10:43:47.804-04:00">DRAFT</status_change>
            <status_change date="2009-04-13T04:00:28.239-04:00">INTERIM</status_change>
            <status_change date="2009-05-04T04:00:36.679-04:00">ACCEPTED</status_change>
            <modified comment="Added additional affected platfroms" date="2009-09-24T11:17:00.434-04:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2009-09-28T04:00:32.351-04:00">INTERIM</status_change>
            <status_change date="2009-10-26T04:00:04.951-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:09.728-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:09.728-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:10.344-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6210 - modified inventory of Internet Explorer 8" date="2014-01-21T17:03:00.601-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-01-21T17:05:26.764-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-24T04:03:24.451-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Internet Explorer 8 is installed" test_ref="oval:org.mitre.oval:tst:9082"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6150" version="8" class="inventory">
      <metadata>
        <title>Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_server_2008::sp2:itanium"/>
        <description>The operating system installed on the system is Microsoft Windows Server 2008 Itanium Edition Service Pack 2</description>
        <oval_repository>
          <dates>
            <submitted date="2009-05-04T16:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <modified comment="Updated comment to include Vista and Server 2008" date="2009-05-07T10:32:00.713-04:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2009-05-07T11:17:27.535-04:00">DRAFT</status_change>
            <status_change date="2009-05-25T04:02:02.357-04:00">INTERIM</status_change>
            <status_change date="2009-06-22T04:00:30.433-04:00">ACCEPTED</status_change>
            <modified comment="Changed the tests for ia64, SP2, and windows to be case insensitive" date="2009-12-02T16:05:00.749-04:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <status_change date="2009-12-02T16:05:00.749-04:00">INTERIM</status_change>
            <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:54:00.233-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <status_change date="2009-12-21T04:00:47.950-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6150 - Corrected the CPE names for Windows Server 2008" date="2010-12-21T10:57:00.617-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2010-12-21T11:00:20.359-05:00">INTERIM</status_change>
            <status_change date="2011-02-07T04:00:14.142-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:43:51.991-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:03:16.905-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criterion comment="Windows Server 2008 is installed" test_ref="oval:org.mitre.oval:tst:7697"/>
        <criterion comment="a version of Windows for the ia64 architecture is installed" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="Win2K/XP/2003/Vista/2008 service pack 2 is installed" test_ref="oval:org.mitre.oval:tst:3019"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6124" version="7" class="inventory">
      <metadata>
        <title>Microsoft Windows Vista (32-bit) Service Pack 2 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_vista::sp2:x86"/>
        <description>The operating system installed on the system is Microsoft Windows Vista (32-bit) Service Pack 2</description>
        <oval_repository>
          <dates>
            <submitted date="2009-05-04T16:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <modified comment="Updated comment to include Vista and Server 2008" date="2009-05-07T10:32:00.713-04:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2009-05-07T11:17:28.873-04:00">DRAFT</status_change>
            <status_change date="2009-05-25T04:02:00.040-04:00">INTERIM</status_change>
            <status_change date="2009-06-22T04:00:28.642-04:00">ACCEPTED</status_change>
            <modified comment="Changed registry check for amd64 to be a case insensitive equals" date="2009-09-04T10:48:00.140-05:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2009-09-07T04:00:27.692-04:00">INTERIM</status_change>
            <status_change date="2009-09-28T04:00:15.275-04:00">ACCEPTED</status_change>
            <modified comment="Replaced negation of test for x64 with a case insensitive test for x86 and changed the tests for SP2, Vista, and windows to be case insensitive" date="2009-12-02T16:05:00.749-04:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <status_change date="2009-12-02T16:05:00.749-04:00">INTERIM</status_change>
            <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:55:00.401-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <modified comment="Updating regex to include parenthesis" date="2009-12-08T17:31:00.669-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <status_change date="2010-01-04T04:01:42.790-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:44:31.595-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:03:16.527-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criterion comment="Windows Vista is installed" test_ref="oval:org.mitre.oval:tst:7914"/>
        <criterion comment="a version of Windows for the x86 architecture is installed" test_ref="oval:org.mitre.oval:tst:3823"/>
        <criterion comment="Win2K/XP/2003/Vista/2008 service pack 2 is installed" test_ref="oval:org.mitre.oval:tst:3019"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5954" version="8" class="inventory">
      <metadata>
        <title>Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_server_2008:r2::itanium"/>
        <description>The operating system installed on the system is Microsoft Windows Server 2008
          R2 Itanium Edition</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-13T13:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-10-22T17:36:49.462-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:29.206-05:00">INTERIM</status_change>
            <status_change date="2009-11-30T04:00:15.509-05:00">ACCEPTED</status_change>
            <modified comment="Changed the tests for 2008 R2, ia64, and windows to be case insensitive" date="2009-12-02T16:05:00.749-04:00">
              <contributor organization="National Institute of Standards and Technology">Tim
                Harrison</contributor>
            </modified>
            <status_change date="2009-12-02T16:05:00.749-04:00">INTERIM</status_change>
            <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:56:00.439-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim
                Harrison</contributor>
            </modified>
            <modified comment="Updating regex to include parenthesis" date="2009-12-08T17:32:00.144-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim
                Harrison</contributor>
            </modified>
            <status_change date="2010-01-04T04:01:41.428-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5954 - Corrected the CPE names for Windows Server 2008" date="2010-12-21T10:57:00.617-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2010-12-21T11:00:20.491-05:00">INTERIM</status_change>
            <status_change date="2011-02-07T04:00:13.727-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5954 - Modifications vary from minor OVAL title/description changes to suggesting an alternative CPE name to use." date="2011-09-28T11:29:00.976-04:00">
              <contributor organization="The MITRE Corporation">David Rothenberg</contributor>
            </modified>
            <status_change date="2011-09-28T11:33:18.116-04:00">INTERIM</status_change>
            <status_change date="2011-10-17T04:00:21.723-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:09.884-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:09.884-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:08.333-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criterion comment="Windows Server 2008 R2 is installed" test_ref="oval:org.mitre.oval:tst:10317"/>
        <criterion comment="a version of Windows for the ia64 architecture is installed" test_ref="oval:org.mitre.oval:tst:2747"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5950" version="7" class="inventory">
      <metadata>
        <title>Microsoft Windows 7 x64 Edition is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_7:::x64"/>
        <description>The operating system installed on the system is Microsoft Windows 7 x64 Edition</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-08T11:27:37.975-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-09-08T20:49:38.713-04:00">DRAFT</status_change>
            <status_change date="2009-09-28T04:00:13.304-04:00">INTERIM</status_change>
            <status_change date="2009-10-26T04:00:04.351-04:00">ACCEPTED</status_change>
            <modified comment="Changed registry check for amd64 to be case insensitive equals" date="2009-11-19T18:33:00.593-05:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2009-11-19T18:35:09.654-05:00">INTERIM</status_change>
            <modified comment="Changed the tests for Windows 7 and windows to be case insensitive" date="2009-12-02T16:05:00.749-04:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:55:00.171-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <modified comment="Updating regex to include parenthesis" date="2009-12-08T17:32:00.647-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <status_change date="2010-01-04T04:01:41.003-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:3180 - new inventory for SQL Server 2008 R2 64-bit" date="2013-07-05T09:33:00.078-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-05T09:37:46.752-04:00">INTERIM</status_change>
            <status_change date="2013-07-22T04:03:08.941-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5027 - removed extraneous whitespace from regex" date="2015-05-21T13:26:00.569-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-05-21T13:29:02.568-04:00">INTERIM</status_change>
            <status_change date="2015-06-08T04:00:17.245-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criterion comment="Windows 7 is installed" test_ref="oval:org.mitre.oval:tst:10792"/>
        <criterion comment="a version of Windows for the x64 architecture is installed" test_ref="oval:org.mitre.oval:tst:3653"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5667" version="6" class="inventory">
      <metadata>
        <title>Microsoft Windows Server 2008 (ia-64) is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_server_2008:::itanium"/>
        <description>The operating system installed on the system is Microsoft Windows Server 2008
          Itanium Edition</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-08T14:18:00">
              <contributor organization="Secure Elements, Inc.">Jeff Ito</contributor>
            </submitted>
            <status_change date="2008-07-11T10:55:58.360-04:00">DRAFT</status_change>
            <status_change date="2008-07-28T04:00:20.824-04:00">INTERIM</status_change>
            <status_change date="2008-08-18T04:00:47.533-04:00">ACCEPTED</status_change>
            <modified comment="Added a negated test for 2008 R2 and changed the tests for ia-64 and windows to be case insensitive" date="2009-12-02T16:05:00.749-04:00">
              <contributor organization="National Institute of Standards and Technology">Tim
                Harrison</contributor>
            </modified>
            <status_change date="2009-12-02T16:05:00.749-04:00">INTERIM</status_change>
            <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:54:00.233-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim
                Harrison</contributor>
            </modified>
            <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:56:00.439-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim
                Harrison</contributor>
            </modified>
            <modified comment="Updating regex to include parenthesis" date="2009-12-08T17:32:00.144-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim
                Harrison</contributor>
            </modified>
            <status_change date="2010-01-04T04:01:38.631-05:00">ACCEPTED</status_change>
            <modified comment="Removed the SP1 component in the CPE reference" date="2010-01-08T15:43:00.851-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2010-01-08T15:44:06.864-05:00">INTERIM</status_change>
            <status_change date="2010-01-25T04:00:06.763-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5667 - Corrected the CPE names for Windows Server 2008" date="2010-12-21T10:57:00.617-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2010-12-21T11:00:21.141-05:00">INTERIM</status_change>
            <status_change date="2011-02-07T04:00:13.308-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criterion comment="Windows Server 2008 is installed" test_ref="oval:org.mitre.oval:tst:7697"/>
        <criterion comment="a version of Windows for the ia64 architecture is installed" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion negate="true" comment="Windows Server 2008 R2 is installed" test_ref="oval:org.mitre.oval:tst:10317"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5653" version="9" class="inventory">
      <metadata>
        <title>Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_server_2008::sp2:x86"/>
        <description>The operating system installed on the system is Microsoft Windows Server 2008 (32-bit) Service Pack 2</description>
        <oval_repository>
          <dates>
            <submitted date="2009-05-04T16:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-05-07T11:17:37.121-04:00">DRAFT</status_change>
            <status_change date="2009-05-25T04:01:42.700-04:00">INTERIM</status_change>
            <status_change date="2009-06-22T04:00:24.249-04:00">ACCEPTED</status_change>
            <modified comment="Changed registry check for amd64 to be a case insensitive equals" date="2009-09-04T10:48:00.140-05:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2009-09-07T04:00:26.467-04:00">INTERIM</status_change>
            <status_change date="2009-09-28T04:00:07.133-04:00">ACCEPTED</status_change>
            <modified comment="Replaced negation of test for x64 with a case insensitive test for x86, added a negated test for 2008 R2 and changed the tests for SP2 and windows to be case insensitive" date="2009-12-02T16:05:00.749-04:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <status_change date="2009-12-02T16:05:00.749-04:00">INTERIM</status_change>
            <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:54:00.233-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:56:00.439-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <modified comment="Updating regex to include parenthesis" date="2009-12-08T17:32:00.144-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <status_change date="2010-01-04T04:01:38.208-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5653 - Corrected the CPE names for Windows Server 2008" date="2010-12-21T10:57:00.617-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2010-12-21T11:00:21.376-05:00">INTERIM</status_change>
            <status_change date="2011-02-07T04:00:12.818-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:40.947-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:03:12.167-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criterion comment="Windows Server 2008 is installed" test_ref="oval:org.mitre.oval:tst:7697"/>
        <criterion comment="a version of Windows for the x86 architecture is installed" test_ref="oval:org.mitre.oval:tst:3823"/>
        <criterion comment="Win2K/XP/2003/Vista/2008 service pack 2 is installed" test_ref="oval:org.mitre.oval:tst:3019"/>
        <criterion negate="true" comment="Windows Server 2008 R2 is installed" test_ref="oval:org.mitre.oval:tst:10317"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5594" version="9" class="inventory">
      <metadata>
        <title>Microsoft Windows Vista x64 Edition Service Pack 2 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_vista::sp2:x64"/>
        <description>The operating system installed on the system is Microsoft Windows Vista x64 Edition Service Pack 2</description>
        <oval_repository>
          <dates>
            <submitted date="2009-05-04T16:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <modified comment="Updated comment to include Vista and Server 2008" date="2009-05-07T10:32:00.713-04:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2009-05-07T11:17:43.459-04:00">DRAFT</status_change>
            <status_change date="2009-05-25T04:01:41.151-04:00">INTERIM</status_change>
            <status_change date="2009-06-22T04:00:22.934-04:00">ACCEPTED</status_change>
            <modified comment="Changed registry check for amd64 to be a case insensitive equals" date="2009-09-04T10:48:00.140-05:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2009-09-07T04:00:26.214-04:00">INTERIM</status_change>
            <status_change date="2009-09-28T04:00:05.829-04:00">ACCEPTED</status_change>
            <modified comment="Changed registry check for amd64 to be case insensitive equals" date="2009-11-19T18:33:00.593-05:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2009-11-19T18:35:08.959-05:00">INTERIM</status_change>
            <modified comment=" Changed the tests for SP2, Vista, and windows to be case insensitive" date="2009-12-02T16:05:00.749-04:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:55:00.401-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <modified comment="Updating regex to include parenthesis" date="2009-12-08T17:31:00.669-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <status_change date="2010-01-04T04:01:35.796-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:44:50.876-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:03:10.996-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:3180 - new inventory for SQL Server 2008 R2 64-bit" date="2013-07-05T09:33:00.078-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-05T09:37:50.680-04:00">INTERIM</status_change>
            <status_change date="2013-07-22T04:03:07.450-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criterion comment="Windows Vista is installed" test_ref="oval:org.mitre.oval:tst:7914"/>
        <criterion comment="a version of Windows for the x64 architecture is installed" test_ref="oval:org.mitre.oval:tst:3653"/>
        <criterion comment="Win2K/XP/2003/Vista/2008 service pack 2 is installed" test_ref="oval:org.mitre.oval:tst:3019"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5356" version="8" class="inventory">
      <metadata>
        <title>Microsoft Windows Server 2008 (64-bit) is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_server_2008:::x64"/>
        <description>The operating system installed on the system is Microsoft Windows Server 2008
          (64-bit)</description>
        <oval_repository>
          <dates>
            <submitted date="2008-03-26T10:44:02">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-03-26T16:27:25.493-04:00">DRAFT</status_change>
            <modified comment="Changed the CPE reference" date="2008-04-04T11:17:00.340-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2008-04-21T04:00:21.761-04:00">INTERIM</status_change>
            <status_change date="2008-05-12T04:00:15.160-04:00">ACCEPTED</status_change>
            <modified comment="Changed registry check for amd64 to be case insensitive equals" date="2009-11-19T18:33:00.593-05:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2009-11-19T18:35:09.355-05:00">INTERIM</status_change>
            <modified comment="Added a negated test for 2008 R2 and changed the test for windows to be case insensitive" date="2009-12-02T16:05:00.749-04:00">
              <contributor organization="National Institute of Standards and Technology">Tim
                Harrison</contributor>
            </modified>
            <status_change date="2009-12-02T16:05:00.749-04:00">INTERIM</status_change>
            <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:54:00.233-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim
                Harrison</contributor>
            </modified>
            <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:56:00.439-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim
                Harrison</contributor>
            </modified>
            <modified comment="Updating regex to include parenthesis" date="2009-12-08T17:32:00.144-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim
                Harrison</contributor>
            </modified>
            <status_change date="2010-01-04T04:01:35.383-05:00">ACCEPTED</status_change>
            <modified comment="Removed the SP1 component in the CPE reference" date="2010-01-08T15:44:00.632-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2010-01-08T15:44:32.646-05:00">INTERIM</status_change>
            <status_change date="2010-01-25T04:00:02.861-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5356 - Corrected the CPE names for Windows Server 2008" date="2010-12-21T10:57:00.617-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2010-12-21T11:00:20.063-05:00">INTERIM</status_change>
            <status_change date="2011-02-07T04:00:12.352-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:3180 - new inventory for SQL Server 2008 R2 64-bit" date="2013-07-05T09:33:00.078-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-05T09:37:47.593-04:00">INTERIM</status_change>
            <status_change date="2013-07-22T04:03:06.694-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criterion comment="Windows Server 2008 is installed" test_ref="oval:org.mitre.oval:tst:7697"/>
        <criterion comment="a version of Windows for the x64 architecture is installed" test_ref="oval:org.mitre.oval:tst:3653"/>
        <criterion negate="true" comment="Windows Server 2008 R2 is installed" test_ref="oval:org.mitre.oval:tst:10317"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5254" version="9" class="inventory">
      <metadata>
        <title>Microsoft Windows Vista x64 Edition Service Pack 1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_vista::sp1:x64"/>
        <description>The operating system installed on the system is Microsoft Windows Vista x64 Edition Service Pack 1</description>
        <oval_repository>
          <dates>
            <submitted date="2008-03-26T10:44:02">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-03-26T16:27:29.700-04:00">DRAFT</status_change>
            <modified comment="Changed the CPE reference" date="2008-04-04T11:17:00.236-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2008-04-21T04:00:21.267-04:00">INTERIM</status_change>
            <status_change date="2008-05-12T04:00:14.836-04:00">ACCEPTED</status_change>
            <modified comment="Changed registry check for amd64 to be a case insensitive equals" date="2009-09-04T10:48:00.140-05:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2009-09-07T04:00:25.662-04:00">INTERIM</status_change>
            <status_change date="2009-09-28T04:00:03.631-04:00">ACCEPTED</status_change>
            <modified comment="Changed registry check for amd64 to be case insensitive equals" date="2009-11-19T18:33:00.593-05:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2009-11-19T18:35:10.408-05:00">INTERIM</status_change>
            <modified comment="Changed the tests for SP1, Vista, and windows to be case insensitive" date="2009-12-02T16:05:00.749-04:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:55:00.401-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <modified comment="Updating regex to include parenthesis" date="2009-12-08T17:31:00.669-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <status_change date="2010-01-04T04:01:34.743-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:44:07.861-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:03:09.530-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:3180 - new inventory for SQL Server 2008 R2 64-bit" date="2013-07-05T09:33:00.078-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-05T09:37:50.242-04:00">INTERIM</status_change>
            <status_change date="2013-07-22T04:03:06.131-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criterion comment="Windows Vista is installed" test_ref="oval:org.mitre.oval:tst:7914"/>
        <criterion comment="a version of Windows for the x64 architecture is installed" test_ref="oval:org.mitre.oval:tst:3653"/>
        <criterion comment="Win2K/XP/2003/Vista service pack 1 is installed" test_ref="oval:org.mitre.oval:tst:2843"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4870" version="6" class="inventory">
      <metadata>
        <title>Microsoft Windows Server 2008 (32-bit) is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_server_2008:::x86"/>
        <description>The operating system installed on the system is Microsoft Windows Server 2008
          (32-bit)</description>
        <oval_repository>
          <dates>
            <submitted date="2008-03-26T10:44:02">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-03-26T16:27:25.280-04:00">DRAFT</status_change>
            <modified comment="Changed the CPE reference" date="2008-04-04T11:17:00.555-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2008-04-21T04:00:20.181-04:00">INTERIM</status_change>
            <status_change date="2008-05-12T04:00:10.618-04:00">ACCEPTED</status_change>
            <modified comment="Changed registry check for amd64 to be a case insensitive equals" date="2009-09-04T10:48:00.140-05:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2009-09-07T04:00:25.188-04:00">INTERIM</status_change>
            <status_change date="2009-09-28T04:00:03.365-04:00">ACCEPTED</status_change>
            <modified comment="Replaced negation of test for x64 with a case insensitive test for x86, added a negated test for 2008 R2, and changed the test for windows to be case insensitive" date="2009-12-02T16:05:00.749-04:00">
              <contributor organization="National Institute of Standards and Technology">Tim
                Harrison</contributor>
            </modified>
            <status_change date="2009-12-02T16:05:00.749-04:00">INTERIM</status_change>
            <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:54:00.233-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim
                Harrison</contributor>
            </modified>
            <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:56:00.439-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim
                Harrison</contributor>
            </modified>
            <modified comment="Updating regex to include parenthesis" date="2009-12-08T17:32:00.144-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim
                Harrison</contributor>
            </modified>
            <status_change date="2010-01-04T04:01:33.629-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:4870 - Corrected the CPE names for Windows Server 2008" date="2010-12-21T10:57:00.617-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2010-12-21T11:00:20.655-05:00">INTERIM</status_change>
            <status_change date="2011-02-07T04:00:11.791-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criterion comment="Windows Server 2008 is installed" test_ref="oval:org.mitre.oval:tst:7697"/>
        <criterion comment="a version of Windows for the x86 architecture is installed" test_ref="oval:org.mitre.oval:tst:3823"/>
        <criterion negate="true" comment="Windows Server 2008 R2 is installed" test_ref="oval:org.mitre.oval:tst:10317"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:116" version="7" class="vulnerability">
      <metadata>
        <title>DHTML Script Function Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5581" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5581"/>
        <description>Unspecified vulnerability in Microsoft Internet Explorer 6 allows remote attackers to execute arbitrary code via certain DHTML script functions, such as normalize, and "incorrectly created elements" that trigger memory corruption, aka "DHTML Script Function Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-12-13T08:17:04">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-12-14T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:53:48.603-05:00">INTERIM</status_change>
            <modified comment="Added an anchor to the regex used to check for Internet Explorer 6." date="2007-01-11T20:38:00.950-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-20T13:39:33.858-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:2185 - Anchored regular expression" date="2011-02-22T12:51:00.261-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:52:30.743-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:00:08.711-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:34.500-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:09.797-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:116 - Addressed validation errors and duplicate extended definitions" date="2015-07-13T20:21:00.869-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:25:22.539-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:00:13.712-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Server 2003-Gold">
          <extend_definition comment="Microsoft Windows Server 2003 (x86) Gold is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.605" test_ref="oval:org.mitre.oval:tst:92"/>
        </criteria>
        <criteria comment="XP,SP1 (64-bit) and Server 2003, SP1">
          <criteria operator="OR" comment="Windows XP (64-bit,SP1) or Server 2003 (SP1) is installed">
            <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2817" test_ref="oval:org.mitre.oval:tst:90"/>
        </criteria>
        <criteria comment="IE 6 on Windows XP,SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Mshtml.dll version is less than 6.0.2900.3020" test_ref="oval:org.mitre.oval:tst:132"/>
        </criteria>
        <criteria comment="IE 6 on Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1586" test_ref="oval:org.mitre.oval:tst:89"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11596" version="3" class="vulnerability">
      <metadata>
        <title>Stack-based buffer overflow in the Intel Indeo41 codec</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4310" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4310"/>
        <description>Stack-based buffer overflow in the Intel Indeo41 codec for Windows Media Player in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via crafted compressed video data in an IV41 stream in a media file, leading to many loop iterations, as demonstrated by data in an AVI file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-09-14T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-11-10T17:01:31.137-05:00">DRAFT</status_change>
            <status_change date="2010-11-29T04:00:04.853-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:13.659-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4 or later">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Aclayers.dll is less than 5.0.2195.7358" test_ref="oval:org.mitre.oval:tst:40913"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="the version of Aclayers.dll is less than 5.1.2600.3647" test_ref="oval:org.mitre.oval:tst:41750"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of Aclayers.dll is less than 5.1.2600.5906" test_ref="oval:org.mitre.oval:tst:41843"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criteria operator="OR">
            <criterion comment="the version of Aclayers.dll is less than 5.2.3790.4624" test_ref="oval:org.mitre.oval:tst:41702"/>
            <criterion comment="the version of Waclayers.dll is less than 5.2.3790.4624" test_ref="oval:org.mitre.oval:tst:40983"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1159" version="7" class="vulnerability">
      <metadata>
        <title>Windows 2000 COM Structured Storage Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>COM Internet Services</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0047" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0047"/>
        <description>Windows 2000, XP, and Server 2003 does not properly "validate the use of memory regions" for COM structured storage files, which allows attackers to execute arbitrary code, aka the "COM Structured Storage Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-02-15T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-02-18T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-29T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-17T12:00:00.000-04:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2005-06-22T12:35:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected and tightened regular expression in ste:2610" date="2010-12-02T11:46:00.307-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-12-02T11:47:26.501-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:13.319-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:44:02.527-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:00:26.376-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 (sp4 or earlier) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 5 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2790"/>
        </criteria>
        <criterion comment="the version of ole32.dll is less than 5.0.2195.7021" negate="false" test_ref="oval:org.mitre.oval:tst:1109"/>
        <criterion comment="the patch KB873333 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1485"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11585" version="3" class="vulnerability">
      <metadata>
        <title>MPEG Layer-3 Audio Decoder Buffer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1882" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1882"/>
        <description>Multiple buffer overflows in the MPEG Layer-3 Audio Codec for Microsoft DirectShow in l3codecx.ax in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allow remote attackers to execute arbitrary code via an MPEG Layer-3 audio stream in (1) a crafted media file or (2) crafted streaming content, aka "MPEG Layer-3 Audio Decoder Buffer Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-08-10T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-08-16T12:27:38.953-04:00">DRAFT</status_change>
            <status_change date="2010-09-06T04:10:44.694-04:00">INTERIM</status_change>
            <status_change date="2010-09-27T04:00:07.986-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
        </criteria>
        <criteria operator="OR">
          <criterion comment="the version of %SystemRoot%\system32\L3codecx.ax is less than 1.6.0.52" test_ref="oval:org.mitre.oval:tst:41331"/>
          <criterion comment="the version of %SystemRoot%\SysWOW64\L3codecx.ax is less than 1.6.0.52" test_ref="oval:org.mitre.oval:tst:40700"/>
          <criterion comment="the version of %SystemRoot%\SysWOW64\Wl3codecx.ax is less than 1.6.0.52" test_ref="oval:org.mitre.oval:tst:41274"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11573" version="3" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the Indeo (CVE-2009-4312)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4312" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4312"/>
        <description>Unspecified vulnerability in the Indeo codec in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via crafted media content, as reported to Microsoft by Dave Lenoe of Adobe.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-09-14T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2010-11-10T17:01:31.746-05:00">DRAFT</status_change>
            <status_change date="2010-11-29T04:00:03.533-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:11.281-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2000 SP4 or later">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Aclayers.dll is less than 5.0.2195.7358" test_ref="oval:org.mitre.oval:tst:40913"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP2">
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <criterion comment="the version of Aclayers.dll is less than 5.1.2600.3647" test_ref="oval:org.mitre.oval:tst:41750"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP (x86) SP3">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="the version of Aclayers.dll is less than 5.1.2600.5906" test_ref="oval:org.mitre.oval:tst:41843"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2">
          <criteria operator="OR">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criteria operator="OR">
            <criterion comment="the version of Aclayers.dll is less than 5.2.3790.4624" test_ref="oval:org.mitre.oval:tst:41702"/>
            <criterion comment="the version of Waclayers.dll is less than 5.2.3790.4624" test_ref="oval:org.mitre.oval:tst:40983"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2161" version="13" class="inventory">
      <metadata>
        <title>Microsoft Windows Server 2003 SP2 (x64) is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_2003_server::sp2:x64"/>
        <description>A version of Microsoft Windows Server 2003 SP2 (x64) is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-10T18:34:24">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-07-10T18:34:24">DRAFT</status_change>
            <status_change date="2007-08-01T22:26:16.096-04:00">INTERIM</status_change>
            <status_change date="2007-08-20T08:04:40.731-04:00">ACCEPTED</status_change>
            <modified comment="Changed the CPE reference" date="2008-04-04T11:17:00.780-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2008-04-04T11:25:55.801-04:00">INTERIM</status_change>
            <status_change date="2008-04-21T04:00:17.838-04:00">ACCEPTED</status_change>
            <modified comment="Updated comment to include Vista and Server 2008" date="2009-05-07T10:32:00.713-04:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2009-05-07T10:34:06.841-04:00">INTERIM</status_change>
            <status_change date="2009-05-25T04:01:16.916-04:00">ACCEPTED</status_change>
            <modified comment="Changed registry check for amd64 to be a case insensitive equals" date="2009-09-04T10:48:00.140-05:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2009-09-07T04:00:24.581-04:00">INTERIM</status_change>
            <status_change date="2009-09-28T04:00:02.962-04:00">ACCEPTED</status_change>
            <modified comment="Changed registry check for amd64 to be case insensitive equals" date="2009-11-19T18:33:00.593-05:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2009-11-19T18:35:10.494-05:00">INTERIM</status_change>
            <modified comment="Changed the tests for SP2 and windows to be case insensitive and replaced the test for Windows 5.2 with a new test for 2003" date="2009-12-02T16:05:00.749-04:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:56:00.085-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <modified comment="Updating regex to include parenthesis" date="2009-12-08T17:31:00.354-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <status_change date="2010-01-04T04:01:30.656-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2161 - Updated Windows 2003 Server CPE names." date="2011-03-29T13:48:00.699-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-03-29T13:51:32.735-04:00">INTERIM</status_change>
            <status_change date="2011-04-18T04:00:36.357-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:39.604-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:02:23.138-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:3180 - new inventory for SQL Server 2008 R2 64-bit" date="2013-07-05T09:33:00.078-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-05T09:37:51.857-04:00">INTERIM</status_change>
            <status_change date="2013-07-22T04:03:03.760-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criterion comment="Windows Server 2003 is installed" test_ref="oval:org.mitre.oval:tst:11145"/>
        <criterion comment="a version of Windows for the x64 architecture is installed" test_ref="oval:org.mitre.oval:tst:3653"/>
        <criterion comment="Win2K/XP/2003/Vista/2008 service pack 2 is installed" test_ref="oval:org.mitre.oval:tst:3019"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1442" version="11" class="inventory">
      <metadata>
        <title>Microsoft Windows Server 2003 (ia64) SP2 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_server_2003::sp2:itanium"/>
        <description>A version of Microsoft Windows Server 2003 (ia64) Service Pack 2 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-15T09:28:35">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-08-15T09:28:35">DRAFT</status_change>
            <status_change date="2007-10-24T17:10:53.045-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:00:59.698-05:00">ACCEPTED</status_change>
            <modified comment="Changed the CPE reference" date="2008-04-04T11:17:00.098-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2008-04-04T11:23:15.120-04:00">INTERIM</status_change>
            <status_change date="2008-04-21T04:00:12.481-04:00">ACCEPTED</status_change>
            <modified comment="Replaced the test for 'SP2 or later' with a test for strictly 'SP2' and test for Windows 5.2 with a new test for 2003, and changed the tests for ia64, SP2 or later, and windows to be case insensitive" date="2009-12-02T16:05:00.749-04:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <status_change date="2009-12-02T16:05:00.749-04:00">INTERIM</status_change>
            <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:56:00.085-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <modified comment="Updating regex to include parenthesis" date="2009-12-08T17:31:00.354-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <status_change date="2010-01-04T04:01:26.509-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1442 - Updated Windows 2003 Server CPE names." date="2011-03-29T13:48:00.699-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-03-29T13:51:29.335-04:00">INTERIM</status_change>
            <status_change date="2011-04-18T04:00:33.006-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:46:32.389-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:01:00.930-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1442 - Updated CPEs." date="2011-10-04T13:20:00.685-04:00">
              <contributor organization="The MITRE Corporation">David Rothenberg</contributor>
            </modified>
            <status_change date="2011-10-04T13:40:41.251-04:00">INTERIM</status_change>
            <status_change date="2011-10-24T04:00:06.408-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criterion comment="Windows Server 2003 is installed" test_ref="oval:org.mitre.oval:tst:11145"/>
        <criterion comment="a version of Windows for the ia64 architecture is installed" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="Win2K/XP/2003/Vista/2008 service pack 2 is installed" test_ref="oval:org.mitre.oval:tst:3019"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1157" version="1" class="vulnerability">
      <metadata>
        <title>Crystal Reports Business Objects Directory Traversal</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Crystal Enterprise</product>
          <product>Crystal Reports</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0204" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0204"/>
        <description>Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used in Visual Studio .NET 2003 and Outlook 2003 with Business Contact Manager, Microsoft Business Solutions CRM 1.2, and other products, allows remote attackers to read and delete arbitrary files via ".." sequences in the dynamicimag argument to crystalimagehandler.aspx.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-09T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2005-01-18T12:00:00.000-04:00" comment="modified wrt-400 - Changed datatype to int was incorrectly set to binary">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Software section">
          <criterion comment="the version of CrystalDecisions.Web.dll is less than 9.1.9800.9" test_ref="oval:org.mitre.oval:tst:1113"/>
        </criteria>
        <criteria operator="AND" comment="Configuration section">
          <criterion comment="the w3svc service is enabled" test_ref="oval:org.mitre.oval:tst:1112"/>
          <criterion comment="a website linked to the Crystal Reports Viewer is active" test_ref="oval:org.mitre.oval:tst:1111"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1150" version="3" class="vulnerability">
      <metadata>
        <title>Crash on "zero-width non-joiner" Sequence</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2702" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2702"/>
        <description>Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via Unicode sequences with "zero-width non-joiner" characters.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-11T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-12T10:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:2367" date="2007-02-26T08:32:00.241-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-26T08:32:38.875-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:2370" date="2007-03-06T07:46:00.064-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:43.054-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:1444" date="2007-04-23T12:05:00.911-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:19:58.449-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:1445" date="2007-04-23T12:05:00.720-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:10:51.641-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Suite version 1.7.10 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.10 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2535"/>
          <criterion comment="Mozilla Suite version 1.7.10 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2534"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.6 or earlier is installed">
          <criterion comment="Firefox version 1.0.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2533"/>
          <criterion comment="Mozilla Firefox version 1.0.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2532"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:115" version="3" class="vulnerability">
      <metadata>
        <title>Hyperlink Object Function Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference ref_id="CVE-2006-3438" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3438" source="CVE"/>
        <description>Unspecified vulnerability in Microsoft Hyperlink Object Library (hlink.dll), possibly a buffer overflow, allows user-assisted attackers to execute arbitrary code via crafted hyperlinks that are not properly handled when hlink.dll "uses a file containing a malformed function," aka "Hyperlink Object Function Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:28:26.729-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:57:19.875-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:115 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:04:56.463-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:00:05.287-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win2K,SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="The version of Hlink.dll is less than 5.2.3790.2748." test_ref="oval:org.mitre.oval:tst:180"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP1">
          <extend_definition comment="Microsoft Windows XP SP1 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          <criterion comment="The version of Hlink.dll is less than 5.2.3790.2748." test_ref="oval:org.mitre.oval:tst:180"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="The version of Hlink.dll is less than 5.2.3790.2748." test_ref="oval:org.mitre.oval:tst:180"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP1 (64-bit)">
          <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="The version of Hlink.dll is less than 5.2.3790.2748." test_ref="oval:org.mitre.oval:tst:180"/>
        </criteria>
        <criteria operator="AND" comment="S03-Gold">
          <extend_definition comment="Microsoft Windows Server 2003 (x86) Gold is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="The version of Hlink.dll is less than 5.2.3790.560." test_ref="oval:org.mitre.oval:tst:114"/>
        </criteria>
        <criteria operator="AND" comment="S03,SP1">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="The version of Hlink.dll is less than 5.2.3790.2748." test_ref="oval:org.mitre.oval:tst:180"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1146" version="9" class="vulnerability">
      <metadata>
        <title>FTP Download Destination Tampering Vulnerability (Windows 2000)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2126" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2126"/>
        <description>The FTP client in Windows XP SP1 and Server 2003, and Internet Explorer 6 SP1 on Windows 2000 SP4, when "Enable Folder View for FTP Sites" is enabled and the user manually initiates a file transfer, allows user-assisted, remote FTP servers to overwrite files in arbitrary locations via crafted filenames.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-31T12:00:00.000-04:00" comment="removed an incorrect leading ^ from the value entity of ste:2402">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-31T00:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:12.684-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:45:56.043-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:33.467-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1146 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:04:42.834-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:00:24.976-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:40.547-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:09.447-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Windows 2000 is installed" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="Win2K/XP/2003 service pack 4 is installed" test_ref="oval:org.mitre.oval:tst:2569"/>
        <criterion comment="Internet Explorer 6 Service Pack 1 is installed" test_ref="oval:org.mitre.oval:tst:2919"/>
        <criterion comment="msieftp.dll is less than 5.50.4956.500" test_ref="oval:org.mitre.oval:tst:1125"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1145" version="4" class="vulnerability">
      <metadata>
        <title>ISA Server Poison Cache Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Security and Acceleration Server 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1215" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1215"/>
        <description>Microsoft ISA Server 2000 allows remote attackers to poison the ISA cache or bypass content restriction policies via a malformed HTTP request packet containing multiple Content-Length headers.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-23T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-06-29T04:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-07-27T04:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T04:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-19T04:00:00.000-04:00" comment="modified wft-81 - Removed extra trailing \\ on registry component.">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1145 - Corrected capitalization and extra spacing errors in product names" date="2011-04-08T16:13:00.153-04:00">
              <contributor organization="AIST">Akihito Nakamura</contributor>
            </modified>
            <status_change date="2011-04-08T16:17:38.277-04:00">INTERIM</status_change>
            <status_change date="2011-04-25T04:00:03.443-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="ISA Server 2000 SP2 (or earlier) is installed" test_ref="oval:org.mitre.oval:tst:2611"/>
        <criterion comment="the version of w3proxy.exe is less than 3.0.1200.430" test_ref="oval:org.mitre.oval:tst:2610"/>
        <criterion negate="true" comment="the patch KB899753 is installed" test_ref="oval:org.mitre.oval:tst:2609"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1141" version="3" class="vulnerability">
      <metadata>
        <title>FTP Server Response Parsing Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0217" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0217"/>
        <description>The wininet.dll FTP client code in Microsoft Internet Explorer 5.01 and 6 might allow remote attackers to execute arbitrary code via an FTP server response of a specific length that causes a terminating null byte to be written outside of a buffer, which causes heap corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-02-14T09:49:32">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-02-16T21:55:00.000-04:00">DRAFT</status_change>
            <modified comment="Corrected affected platform name to Microsoft Windows Server 2003. Implemented by Jon Baker of The MITRE Corporation." date="2007-02-20T19:29:00.895-05:00">
              <contributor organization="Secure Elements, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:42.873-04:00">INTERIM</status_change>
            <status_change date="2007-04-10T13:44:18.827-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1141 - Addressed validation errors and duplicate extended definitions" date="2015-07-13T20:21:00.869-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:25:26.295-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:00:12.034-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Server 2003-Gold (IE7)">
          <extend_definition comment="Microsoft Windows Server 2003 (x86) Gold is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="the version of mshtml.dll is less than 7.0.6000.16414" test_ref="oval:org.mitre.oval:tst:3906"/>
        </criteria>
        <criteria comment="XP,SP1 (64-bit) and Server 2003, SP1 (IE7)">
          <criteria operator="OR" comment="Windows XP (64-bit,SP1) or Server 2003 (SP1) is installed">
            <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="the version of mshtml.dll is less than 7.0.6000.16414" test_ref="oval:org.mitre.oval:tst:3906"/>
        </criteria>
        <criteria comment="IE 7 on Windows XP,SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="the version of mshtml.dll is less than 7.0.6000.16414" test_ref="oval:org.mitre.oval:tst:3906"/>
        </criteria>
        <criteria comment="Server 2003-Gold">
          <extend_definition comment="Microsoft Windows Server 2003 (x86) Gold is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.630" test_ref="oval:org.mitre.oval:tst:3764"/>
        </criteria>
        <criteria comment="XP,SP1 (64-bit) and Server 2003, SP1 (IE6)">
          <criteria operator="OR" comment="Windows XP (64-bit,SP1) or Server 2003 (SP1) is installed">
            <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2858" test_ref="oval:org.mitre.oval:tst:3187"/>
        </criteria>
        <criteria comment="IE 6 on Windows XP,SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2900.3059" test_ref="oval:org.mitre.oval:tst:4144"/>
        </criteria>
        <criteria comment="IE 6 on Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1589" test_ref="oval:org.mitre.oval:tst:3560"/>
        </criteria>
        <criteria comment="IE 5.01,SP4 on Win2k,SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3849.500" test_ref="oval:org.mitre.oval:tst:3802"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1140" version="4" class="vulnerability">
      <metadata>
        <title>IE6,SP1 JPEG Image Rendering Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1988" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1988"/>
        <description>Unknown vulnerability in Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to execute arbitrary code via a web site or an HTML e-mail containing a crafted JPEG image that causes memory corruption, aka "JPEG Image Rendering Memory Corruption Vulnerability".</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-23T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-08-25T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:45:57.656-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:32.964-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:40.727-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:09.128-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
        <criteria operator="OR" comment="the version of mshtml.dll is less than 6.0.2800.1515 or 6.0.2800.1516">
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1515 (RTMGDR)" negate="false" test_ref="oval:org.mitre.oval:tst:2418"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1516 (RTMQFE)" negate="false" test_ref="oval:org.mitre.oval:tst:2417"/>
        </criteria>
        <criterion comment="the patch kb896727 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1129"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1133" version="5" class="vulnerability">
      <metadata>
        <title>Scob and Toofer Internet Explorer v6.0,SP1 Vulnerabilities</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0549" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0549"/>
        <description>The WebBrowser ActiveX control, or the Internet Explorer HTML rendering engine (MSHTML), as used in Internet Explorer 6, allows remote attackers to execute arbitrary code in the Local Security context by using the showModalDialog method and modifying the location to execute code such as Javascript, as demonstrated using (1) delayed HTTP redirect operations, and an HTTP response with a Location: header containing a "URL:" prepended to a "ms-its" protocol URI, or (2) modifying the location attribute of the window, as exploited by the Download.ject (aka Scob aka Toofer) using the ADODB.Stream object.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-08-02T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T11:01:00.000-04:00" comment="modified wft-267 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:46:06.728-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:32.598-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:42.193-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:08.969-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1458" negate="false" test_ref="oval:org.mitre.oval:tst:2765"/>
          <criterion comment="the patch kb832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2802"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11304" version="4" class="vulnerability">
      <metadata>
        <title>Stack-based buffer overflow in SigPlus Pro 3.74 ActiveX control</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>SigPlus Pro ActiveX control</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2931" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2931"/>
        <description>Stack-based buffer overflow in SigPlus Pro 3.74 ActiveX control allows remote attackers to execute arbitrary code via a long eighth argument (HexString) to the LCDWriteString method.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-08-17T15:41:23">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </submitted>
            <status_change date="2010-08-17T12:53:41.719-04:00">DRAFT</status_change>
            <modified comment="Optimized pattern matching by removing the capturing groups." date="2010-08-25T16:08:00.522-04:00">
              <contributor organization="The MITRE Corporation">Nate Przybyszewski</contributor>
            </modified>
            <status_change date="2010-09-13T04:00:05.167-04:00">INTERIM</status_change>
            <status_change date="2010-10-04T04:00:04.405-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="SigPlus Pro ActiveX control is installed" definition_ref="oval:org.mitre.oval:def:12020"/>
        <criterion comment="Check if the version of Topaz e-Signatures SigPlus is 3.74" test_ref="oval:org.mitre.oval:tst:41770"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12020" version="4" class="inventory">
      <metadata>
        <title>SigPlus Pro ActiveX control is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>SigPlus Pro ActiveX control</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:topazsystems:sigplus_pro_activex_control"/>
        <description>SigPlus Pro ActiveX control is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2010-08-17T17:47:08">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </submitted>
            <status_change date="2010-08-17T12:53:41.400-04:00">DRAFT</status_change>
            <modified comment="Optimized pattern matching by removing the capturing groups." date="2010-08-25T16:08:00.475-04:00">
              <contributor organization="The MITRE Corporation">Nate Przybyszewski</contributor>
            </modified>
            <status_change date="2010-09-13T04:00:44.788-04:00">INTERIM</status_change>
            <status_change date="2010-10-04T04:00:26.122-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR">
          <extend_definition comment="Microsoft Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP2 is installed" definition_ref="oval:org.mitre.oval:def:754"/>
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
        </criteria>
        <criterion comment="Check if SigPlus Pro ActiveX control is installed" test_ref="oval:org.mitre.oval:tst:41539"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:85" version="5" class="inventory">
      <metadata>
        <title>Microsoft Windows 2000 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_2000"/>
        <description>The operating system installed on the system is Microsoft Windows 2000.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-26T12:55:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2006-06-26T12:55:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added CPE reference." date="2007-04-30T07:48:00.142-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-30T08:03:27.160-04:00">INTERIM</status_change>
            <status_change date="2007-05-23T15:05:53.257-04:00">ACCEPTED</status_change>
            <modified comment="Changed the CPE reference" date="2008-04-04T11:17:00.718-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2008-04-04T11:29:31.741-04:00">INTERIM</status_change>
            <status_change date="2008-04-21T04:00:24.735-04:00">ACCEPTED</status_change>
            <modified comment="Changed the test for windows to be case insensitive" date="2009-12-02T16:05:00.749-04:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <status_change date="2009-12-02T16:05:00.749-04:00">INTERIM</status_change>
            <status_change date="2009-12-21T04:01:19.119-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criterion comment="Windows 2000 is installed" test_ref="oval:org.mitre.oval:tst:2"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:754" version="7" class="inventory">
      <metadata>
        <title>Microsoft Windows XP (x86) SP2 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_xp::sp2:x86"/>
        <description>A version of Microsoft Windows XP (x86) Service Pack 2 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-03-05T09:00:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2007-03-05T09:00:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:17:26.869-04:00">INTERIM</status_change>
            <status_change date="2007-04-10T13:44:28.583-04:00">ACCEPTED</status_change>
            <modified comment="Changed the CPE reference" date="2008-04-04T11:17:00.434-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2008-04-04T11:29:22.458-04:00">INTERIM</status_change>
            <status_change date="2008-04-21T04:00:24.359-04:00">ACCEPTED</status_change>
            <modified comment="Updated comment to include Vista and Server 2008" date="2009-05-07T10:32:00.713-04:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2009-05-07T10:34:02.214-04:00">INTERIM</status_change>
            <status_change date="2009-06-22T04:00:33.535-04:00">ACCEPTED</status_change>
            <modified comment="Changed the tests for x86, SP2, and windows to be case insensitive and replaced the test for Windows 5.1 with a new test for Windows XP" date="2009-12-02T16:05:00.749-04:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <status_change date="2009-12-02T16:05:00.749-04:00">INTERIM</status_change>
            <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:56:00.359-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <modified comment="Updating regex to include parenthesis" date="2009-12-08T17:32:00.792-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <status_change date="2009-12-28T04:00:42.528-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:44:45.277-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:03:25.729-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criterion comment="Windows XP is installed" test_ref="oval:org.mitre.oval:tst:11179"/>
        <criterion comment="a version of Windows for the x86 architecture is installed" test_ref="oval:org.mitre.oval:tst:3823"/>
        <criterion comment="Win2K/XP/2003/Vista/2008 service pack 2 is installed" test_ref="oval:org.mitre.oval:tst:3019"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6165" version="5" class="inventory">
      <metadata>
        <title>Microsoft Windows 7 (32-bit) is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_7:::x86"/>
        <description>The operating system installed on the system is Microsoft Windows 7 (32-bit)</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-08T11:27:37.975-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-09-08T20:49:38.394-04:00">DRAFT</status_change>
            <status_change date="2009-09-28T04:00:16.403-04:00">INTERIM</status_change>
            <status_change date="2009-10-19T04:00:10.283-04:00">ACCEPTED</status_change>
            <modified comment="Replaced negation of test for x64 with a case insensitive test for x86 and changed the tests for Windows 7 and windows to be case insensitive" date="2009-12-02T16:05:00.749-04:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <status_change date="2009-12-02T16:05:00.749-04:00">INTERIM</status_change>
            <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:55:00.171-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <modified comment="Updating regex to include parenthesis" date="2009-12-08T17:32:00.647-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <status_change date="2010-01-04T04:01:43.679-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5027 - removed extraneous whitespace from regex" date="2015-05-21T13:26:00.569-04:00">
              <contributor organization="The MITRE Corporation">Mike Cokus</contributor>
            </modified>
            <status_change date="2015-05-21T13:29:02.657-04:00">INTERIM</status_change>
            <status_change date="2015-06-08T04:00:17.442-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criterion comment="Windows 7 is installed" test_ref="oval:org.mitre.oval:tst:10792"/>
        <criterion comment="a version of Windows for the x86 architecture is installed" test_ref="oval:org.mitre.oval:tst:3823"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5631" version="6" class="inventory">
      <metadata>
        <title>Microsoft Windows XP (x86) SP3 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_xp::sp3:x86"/>
        <description>A version of Microsoft Windows XP (x86) Service Pack 3 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-06-10T14:50:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-06-12T13:58:47.155-04:00">DRAFT</status_change>
            <status_change date="2008-06-30T04:00:18.370-04:00">INTERIM</status_change>
            <status_change date="2008-07-21T04:00:18.901-04:00">ACCEPTED</status_change>
            <modified comment="Changed the tests for x86, SP3, and windows to be case insensitive and replaced the test for Windows 5.1 with a new test for Windows XP" date="2009-12-02T16:05:00.749-04:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <status_change date="2009-12-02T16:05:00.749-04:00">INTERIM</status_change>
            <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:56:00.359-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <modified comment="Updating regex to include parenthesis" date="2009-12-08T17:32:00.792-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <status_change date="2010-01-04T04:01:36.319-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:44:36.981-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:03:11.414-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criterion comment="Windows XP is installed" test_ref="oval:org.mitre.oval:tst:11179"/>
        <criterion comment="a version of Windows for the x86 architecture is installed" test_ref="oval:org.mitre.oval:tst:3823"/>
        <criterion comment="Win2K/XP/2003 service pack 3 is installed" test_ref="oval:org.mitre.oval:tst:7814"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4873" version="6" class="inventory">
      <metadata>
        <title>Microsoft Windows Vista (32-bit) Service Pack 1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_vista::sp1:x86"/>
        <description>The operating system installed on the system is Microsoft Windows Vista (32-bit) Service Pack 1</description>
        <oval_repository>
          <dates>
            <submitted date="2008-03-26T10:44:02">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-03-26T16:27:29.495-04:00">DRAFT</status_change>
            <modified comment="Changed the CPE reference" date="2008-04-04T11:17:00.108-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2008-04-21T04:00:20.428-04:00">INTERIM</status_change>
            <status_change date="2008-05-12T04:00:14.497-04:00">ACCEPTED</status_change>
            <modified comment="Replaced negation of test for x64 with a case insensitive test for x86 and changed the tests for SP1, Vista, and windows to be case insensitive" date="2009-12-02T16:05:00.749-04:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <status_change date="2009-12-02T16:05:00.749-04:00">INTERIM</status_change>
            <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:55:00.401-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <modified comment="Updating regex to include parenthesis" date="2009-12-08T17:31:00.669-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <status_change date="2010-01-04T04:01:34.223-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:45.918-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:03:06.709-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criterion comment="Windows Vista is installed" test_ref="oval:org.mitre.oval:tst:7914"/>
        <criterion comment="a version of Windows for the x86 architecture is installed" test_ref="oval:org.mitre.oval:tst:3823"/>
        <criterion comment="Win2K/XP/2003/Vista service pack 1 is installed" test_ref="oval:org.mitre.oval:tst:2843"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1282" version="4" class="inventory">
      <metadata>
        <title>Microsoft Windows Vista (32-bit) is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_vista:::x86"/>
        <description>The operating system installed on the system is Microsoft Windows Vista
          (32-bit)</description>
        <oval_repository>
          <dates>
            <submitted date="2007-04-11T11:27:37.975-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2007-04-11T12:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-04-30T08:18:46.566-04:00">INTERIM</status_change>
            <status_change date="2007-05-23T15:05:26.800-04:00">ACCEPTED</status_change>
            <modified comment="Vista test updated because of the conflictions with Server 2008" date="2008-03-26T10:51:02.210-04:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2008-03-31T04:00:20.410-04:00">INTERIM</status_change>
            <modified comment="Changed the CPE reference" date="2008-04-04T11:17:00.749-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2008-04-21T04:00:11.683-04:00">ACCEPTED</status_change>
            <modified comment="Replaced negation of test for x64 with a case insensitive test for x86 and changed the tests for Vista and windows to be case insensitive" date="2009-12-02T16:05:00.749-04:00">
              <contributor organization="National Institute of Standards and Technology">Tim
                Harrison</contributor>
            </modified>
            <status_change date="2009-12-02T16:05:00.749-04:00">INTERIM</status_change>
            <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:55:00.401-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim
                Harrison</contributor>
            </modified>
            <modified comment="Updating regex to include parenthesis" date="2009-12-08T17:31:00.669-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim
                Harrison</contributor>
            </modified>
            <status_change date="2010-01-04T04:01:25.664-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criterion comment="Windows Vista is installed" test_ref="oval:org.mitre.oval:tst:7914"/>
        <criterion comment="a version of Windows for the x86 architecture is installed" test_ref="oval:org.mitre.oval:tst:3823"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1120" version="7" class="vulnerability">
      <metadata>
        <title>COM Object Instantiation Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4697" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4697"/>
        <description>Microsoft Internet Explorer 5.01, 6, and 7 uses certain COM objects from Imjpcksid.dll as ActiveX controls, which allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: this issue might be related to CVE-2006-4193.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-02-14T09:49:32">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-02-16T21:55:00.000-04:00">DRAFT</status_change>
            <modified comment="Fixed typo in ste:146, used for file version check for mshtml.dll for Server 2003.  Implemented by Matthew Wojcik." date="2007-03-05T11:43:00.839-05:00">
              <contributor organization="GFI Software">Daniel Tarnu</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:42.248-04:00">INTERIM</status_change>
            <status_change date="2007-04-10T13:44:18.286-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:2185 - Anchored regular expression" date="2011-02-22T12:51:00.261-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:52:31.572-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:00:05.428-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:44.853-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:08.669-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1120 - Addressed validation errors and duplicate extended definitions" date="2015-07-13T20:21:00.869-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:25:24.981-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:00:10.702-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Server 2003-Gold (IE7)">
          <extend_definition comment="Microsoft Windows Server 2003 (x86) Gold is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="the version of mshtml.dll is less than 7.0.6000.16414" test_ref="oval:org.mitre.oval:tst:3906"/>
        </criteria>
        <criteria comment="XP,SP1 (64-bit) and Server 2003, SP1 (IE7)">
          <criteria operator="OR" comment="Windows XP (64-bit,SP1) or Server 2003 (SP1) is installed">
            <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="the version of mshtml.dll is less than 7.0.6000.16414" test_ref="oval:org.mitre.oval:tst:3906"/>
        </criteria>
        <criteria comment="IE 7 on Windows XP,SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="the version of mshtml.dll is less than 7.0.6000.16414" test_ref="oval:org.mitre.oval:tst:3906"/>
        </criteria>
        <criteria comment="Server 2003-Gold">
          <extend_definition comment="Microsoft Windows Server 2003 (x86) Gold is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.630" test_ref="oval:org.mitre.oval:tst:3764"/>
        </criteria>
        <criteria comment="XP,SP1 (64-bit) and Server 2003, SP1 (IE6)">
          <criteria operator="OR" comment="Windows XP (64-bit,SP1) or Server 2003 (SP1) is installed">
            <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2858" test_ref="oval:org.mitre.oval:tst:3187"/>
        </criteria>
        <criteria comment="IE 6 on Windows XP,SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2900.3059" test_ref="oval:org.mitre.oval:tst:4144"/>
        </criteria>
        <criteria comment="IE 6 on Windows 2000">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1589" test_ref="oval:org.mitre.oval:tst:3560"/>
        </criteria>
        <criteria comment="IE 5.01,SP4 on Win2k,SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3849.500" test_ref="oval:org.mitre.oval:tst:3802"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1118" version="7" class="vulnerability">
      <metadata>
        <title>MS Windows RPC DCOM DoS-based Privilege Escalation Vulnerability (Test 2)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Remote Procedure Call (RPC)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0605" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0605"/>
        <description>The RPC DCOM interface in Windows 2000 SP3 and SP4 allows remote attackers to cause a denial of service (crash), and local attackers to use the DoS to hijack the epmapper pipe to gain privileges, via certain messages to the __RemoteGetClassObject interface that cause a NULL pointer to be passed to the PerformScmStage function.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-20T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-17T12:00:00.000-04:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2005-06-22T12:35:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected and tightened regular expression in ste:2610" date="2010-12-02T11:46:00.307-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-12-02T11:47:26.757-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:08.954-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:43:50.391-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:00:20.426-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 (sp4 or earlier) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 5 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2790"/>
        </criteria>
        <criterion comment="the version of rpcrt4.dll is less than 5.0.2195.6802" negate="false" test_ref="oval:org.mitre.oval:tst:2914"/>
        <criterion comment="the patch kb824146 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:3082"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1104" version="3" class="vulnerability">
      <metadata>
        <title>DirectX 9 DirectShow Malicious MIDI File Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>DirectX</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0346" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0346"/>
        <description>Multiple integer overflows in a Microsoft Windows DirectX MIDI library (QUARTZ.DLL) allow remote attackers to execute arbitrary code via a MIDI (.mid) file with (1) large length for a Text or Copyright string, or (2) a large number of tracks, which leads to a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-01-31T06:03:00.000-04:00" comment="Updated reference to CVE-2003-0346.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected obj:832 to look for the q number under the hot fix registry key." date="2007-09-05T16:29:00.747-04:00">
              <contributor organization="Secure Elements, Inc.">Jeff Ito</contributor>
            </modified>
            <status_change date="2007-09-05T16:39:26.942-04:00">INTERIM</status_change>
            <status_change date="2007-09-27T08:57:38.999-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="DirectX 9.0 or 9.0a installed.">
          <criterion comment="DirectX 9.0-gold Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1166"/>
          <criterion comment="DirectX 9.0a Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1165"/>
        </criteria>
        <criterion comment="Patch Windows2000-KB819696-x86-ENU.EXE Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1172"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1103" class="vulnerability" version="1">
      <metadata>
        <title>DirectAnimation ActiveX Controls Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4777" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4777"/>
        <description>Heap-based buffer overflow in the DirectAnimation Path Control (DirectAnimation.PathControl) COM object (daxctle.ocx) for Internet Explorer 6.0 SP1, on Chinese and possibly other Windows distributions, allows remote attackers to execute arbitrary code via unknown manipulations in arguments to the KeyFrame method, possibly related to an integer overflow, as demonstrated by daxctle2, and a different vulnerability than CVE-2006-4446.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-11-15T12:28:05">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-11-17T12:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:53:48.307-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:31.071-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Server 2003-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.594" negate="false" test_ref="oval:org.mitre.oval:tst:71"/>
        </criteria>
        <criteria comment="XP,SP1 (64-bit) and Server 2003, SP1" operator="AND">
          <criteria operator="OR" comment="Windows XP (64-bit,SP1) or Server 2003 (SP1) is installed">
            <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          </criteria>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2795" negate="false" test_ref="oval:org.mitre.oval:tst:70"/>
        </criteria>
        <criteria comment="IE 6 on Windows XP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2900.2995" negate="false" test_ref="oval:org.mitre.oval:tst:66"/>
        </criteria>
        <criteria comment="IE 6 on Windows 2000" operator="AND">
          <extend_definition comment="Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1578" negate="false" test_ref="oval:org.mitre.oval:tst:65"/>
        </criteria>
        <criteria comment="IE 5.01,SP4 on Win2k,SP4" operator="AND">
          <extend_definition comment="Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Internet Explorer 5.01, SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3842.3000" negate="false" test_ref="oval:org.mitre.oval:tst:142"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1097" version="7" class="vulnerability">
      <metadata>
        <title>Win2K/XP,SP1 HTTPS Proxy Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2830" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2830"/>
        <description>Microsoft Internet Explorer 5.01, 5.5, and 6, when using an HTTPS proxy server that requires Basic Authentication, sends URLs in cleartext, which allows remote attackers to obtain sensitive information, aka "HTTPS Proxy Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-12-13T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-16T01:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:46:01.342-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:29.689-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:46:29.598-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:00:18.856-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:57.479-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:08.025-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Win2K or XP,SP1 is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2800.1528" negate="false" test_ref="oval:org.mitre.oval:tst:2390"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1096" version="3" class="vulnerability">
      <metadata>
        <title>IE Web Page Spoofing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0339" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0339"/>
        <description>Internet Explorer 5.5 and earlier allows remote attackers to display a URL in the address bar that is different than the URL that is actually being displayed, which could be used in web site spoofing attacks, aka the "Web page spoofing vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-29T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:57.288-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:07.894-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Internet Explorer 5.5 Installed">
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1466"/>
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1465"/>
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1464"/>
        </criteria>
        <criterion comment="File %windir%\system32\mshtml.dll version is less than 5.50.4616.200" negate="false" test_ref="oval:org.mitre.oval:tst:1171"/>
        <criterion comment="File %windir%\system32\urlmon.dll version is less than 5.50.4701.2400" negate="false" test_ref="oval:org.mitre.oval:tst:1170"/>
        <criterion comment="Patch Q295106 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1461"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1095" version="6" class="vulnerability">
      <metadata>
        <title>DirectX 8 DirectShow Malicious MIDI File Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>DirectX</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0346" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0346"/>
        <description>Multiple integer overflows in a Microsoft Windows DirectX MIDI library (QUARTZ.DLL) allow remote attackers to execute arbitrary code via a MIDI (.mid) file with (1) large length for a Text or Copyright string, or (2) a large number of tracks, which leads to a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-01-31T05:11:00.000-04:00" comment="Updated reference to CVE-2003-0346.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added Microsoft Windows 2003 and Microsoft Windows Server 2003 as affected platfroms. Implemented by Jon Baker of The MITRE Corporation." date="2007-02-12T20:22:00.568-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-02-12T20:25:03.590-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:16:41.281-04:00">ACCEPTED</status_change>
            <modified comment="Corrected obj:832 to look for the q number under the hot fix registry key." date="2007-09-05T16:29:00.747-04:00">
              <contributor organization="Secure Elements, Inc.">Jeff Ito</contributor>
            </modified>
            <status_change date="2007-09-05T16:39:26.828-04:00">INTERIM</status_change>
            <status_change date="2007-09-27T08:57:38.862-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:1047 - obj/ste updates to conform to authoring style guide" date="2013-03-26T09:53:00.500-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-03-26T09:56:04.893-04:00">INTERIM</status_change>
            <status_change date="2013-04-15T04:00:06.203-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="DirectX 8.x Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1173"/>
        <criterion comment="Patch Windows2000-KB819696-x86-ENU.EXE Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1172"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1094" version="4" class="vulnerability">
      <metadata>
        <title>IE plugin.ocx Heap Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0233" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0233"/>
        <description>Heap-based buffer overflow in plugin.ocx for Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code via the Load() method, a different vulnerability than CVE-2003-0115.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2004-09-22T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-09-22T11:10:00.000-04:00" comment="Replaced IE cumulative patch IDs to correspond to the original IDs">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2004-10-06T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:57.615-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:07.767-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
        <criterion comment="the version of mshtml.dll is less than 5.50.4926.2500" negate="false" test_ref="oval:org.mitre.oval:tst:1454"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:109" version="4" class="vulnerability">
      <metadata>
        <title>Windows ntdll.dll Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0109" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0109"/>
        <description>Buffer overflow in ntdll.dll on Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute arbitrary code, as demonstrated via a WebDAV request to IIS 5.0.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified comment="Fixed regex in ste:2889.  Implemented by Matthew Wojcik." date="2007-03-06T18:19:00.507-05:00">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2007-03-06T18:21:13.134-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:16:40.706-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:03.319-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:00:17.953-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 (sp3 or earlier) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="the version of ntdll.dll is less than 5.0.2195.6685" negate="false" test_ref="oval:org.mitre.oval:tst:2938"/>
        <criterion comment="the patch q815021 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2937"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1089" version="3" class="vulnerability">
      <metadata>
        <title>XMLHttpRequest Header Spoofing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2703" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2703"/>
        <description>Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to modify HTTP headers of XML HTTP requests via XMLHttpRequest, and possibly use the client to exploit vulnerabilities in servers or proxies, including HTTP request smuggling and HTTP request splitting.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-11T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-12T10:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:2367" date="2007-02-26T08:32:00.241-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-26T08:32:39.263-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:2370" date="2007-03-06T07:46:00.064-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:40.416-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:1444" date="2007-04-23T12:05:00.911-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:19:58.867-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:1445" date="2007-04-23T12:05:00.720-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:10:51.315-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Suite version 1.7.10 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.10 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2535"/>
          <criterion comment="Mozilla Suite version 1.7.10 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2534"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.6 or earlier is installed">
          <criterion comment="Firefox version 1.0.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2533"/>
          <criterion comment="Mozilla Firefox version 1.0.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2532"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1088" version="1" class="vulnerability">
      <metadata>
        <title>Microsoft Outlook Express 5.5,SP2 News Reading Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Outlook Express</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1213" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1213"/>
        <description>Stack-based buffer overflow in the news reader for Microsoft Outlook Express (MSOE.DLL) 5.5 SP2, 6, and 6 SP1 allows remote malicious NNTP servers to execute arbitrary code via a LIST response with a long second field.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Microsoft Outlook Express 5.5 SP2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1514"/>
        <criterion comment="the version of inetcomm.dll is less than 5.50.4952.2800" negate="false" test_ref="oval:org.mitre.oval:tst:1178"/>
        <criterion comment="Patch KB897715 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2853"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1087" version="3" class="vulnerability">
      <metadata>
        <title>Mozilla JavaScript Garbage-collection Hazard Audit</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1742" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1742"/>
        <description>The JavaScript engine in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 does not properly handle temporary variables that are not garbage collected, which might allow remote attackers to trigger operations on freed memory and cause memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-07T09:05:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:11.874-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:1133" date="2007-02-26T08:08:00.208-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-26T08:09:15.637-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:1135" date="2007-02-26T08:21:00.993-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:1136" date="2007-02-26T08:24:00.848-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:1138" date="2007-02-26T08:25:00.405-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:2283" date="2007-02-26T08:29:00.407-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:2284" date="2007-02-26T08:30:00.724-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:40.116-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:881" date="2007-04-23T12:05:00.811-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:12:53.801-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:882" date="2007-04-23T12:05:00.939-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in obj:883" date="2007-04-23T12:05:00.804-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in obj:1385" date="2007-04-23T12:05:00.430-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:10:50.913-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1268"/>
          <criterion comment="Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1267"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Thunderbird version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1266"/>
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1265"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.12 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1264"/>
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1263"/>
        </criteria>
        <criteria operator="AND" comment="A pre-release of SeaMonkey 1.0 is installed">
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2439"/>
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2438"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1084" version="7" class="vulnerability">
      <metadata>
        <title>COM Object Instantiation Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference ref_id="CVE-2007-0218" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0218" source="CVE"/>
        <description>Microsoft Internet Explorer 5.01 and 6 allows remote attackers to execute arbitrary code by instantiating certain COM objects from Urlmon.dll, which triggers memory corruption during a call to the IObjectSafety function.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-06-13T08:22:59.000-04:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-06-13T15:20:00.000-04:00">DRAFT</status_change>
            <modified comment="Removed IE7 tests." date="2007-06-15T13:52:00.592-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-07-03T14:05:51.089-04:00">INTERIM</status_change>
            <status_change date="2007-07-18T15:57:47.982-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1084 - Updates made to criteria user correct IDs and comments." date="2011-01-07T14:47:00.547-05:00">
              <contributor organization="G2, Inc.">Jeff Cockerill</contributor>
            </modified>
            <status_change date="2011-01-07T14:53:47.926-05:00">INTERIM</status_change>
            <status_change date="2011-01-24T04:00:03.105-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1084 - Correcting incorrect references to 64-bit Itanium XP." date="2012-08-23T17:47:00.168-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-08-23T17:52:40.645-04:00">INTERIM</status_change>
            <status_change date="2012-09-10T04:00:04.605-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:56.175-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:07.322-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 5.01,SP4 on Win2k,SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Internet Explorer 5.01 SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="the version of Mshtml.dll is less than 5.0.3853.3000" test_ref="oval:org.mitre.oval:tst:3507"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win 2k, SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the version of Mshtml.dll is less than 6.0.2800.1595" test_ref="oval:org.mitre.oval:tst:3202"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win XP SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of Mshtml.dll is less than 6.0.2900.3132" test_ref="oval:org.mitre.oval:tst:3224"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win 2k3 SP1">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of Mshtml.dll is less than 6.0.3790.2920" test_ref="oval:org.mitre.oval:tst:3899"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win 2k3 SP2">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of Mshtml.dll is less than 6.0.3790.4064" test_ref="oval:org.mitre.oval:tst:3773"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win XP SP2 (64-bit)">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of Mshtml.dll is less than 6.0.3790.4064" test_ref="oval:org.mitre.oval:tst:3773"/>
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
        </criteria>
        <criteria operator="AND" comment="IE 6 on Win XP SP1 (64-bit)">
          <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of Mshtml.dll is less than 6.0.3790.2920" test_ref="oval:org.mitre.oval:tst:3899"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4193" version="9" class="inventory">
      <metadata>
        <title>Microsoft Windows XP x64 Edition SP2 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_xp::sp2:x64"/>
        <description>A version of Microsoft Windows XP Professional x64 Edition Service Pack 2 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-11-15T15:56:12">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-11-16T08:53:11.596-05:00">DRAFT</status_change>
            <status_change date="2007-12-03T04:06:19.275-05:00">INTERIM</status_change>
            <status_change date="2007-12-24T04:06:02.885-05:00">ACCEPTED</status_change>
            <modified comment="Changed the CPE reference" date="2008-04-04T11:17:00.080-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2008-04-04T11:21:54.103-04:00">INTERIM</status_change>
            <status_change date="2008-04-21T04:00:19.231-04:00">ACCEPTED</status_change>
            <modified comment="Changed registry check for amd64 to be case insensitive equals" date="2009-11-19T18:33:00.593-05:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2009-11-19T18:35:09.716-05:00">INTERIM</status_change>
            <modified comment="Replaced the test for 'SP2 or later' with a test for strictly 'SP2' and the test for Windows 5.1 with a new test for Windows XP and changed the tests for SP2 and windows to be case insensitive" date="2009-12-02T16:05:00.749-04:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:56:00.359-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <modified comment="Updating regex to include parenthesis" date="2009-12-08T17:32:00.792-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <status_change date="2010-01-04T04:01:31.215-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:59.384-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:02:57.302-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:3180 - new inventory for SQL Server 2008 R2 64-bit" date="2013-07-05T09:33:00.078-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-05T09:37:47.108-04:00">INTERIM</status_change>
            <status_change date="2013-07-22T04:03:04.421-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criterion comment="Windows XP is installed" test_ref="oval:org.mitre.oval:tst:11179"/>
        <criterion comment="a version of Windows for the x64 architecture is installed" test_ref="oval:org.mitre.oval:tst:3653"/>
        <criterion comment="Win2K/XP/2003/Vista/2008 service pack 2 is installed" test_ref="oval:org.mitre.oval:tst:3019"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1935" version="11" class="inventory">
      <metadata>
        <title>Microsoft Windows Server 2003 SP2 (x86) is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_server_2003::sp2:x86"/>
        <description>A version of Microsoft Windows Server 2003 Service Pack 2 (x86) is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-04-09T09:49:32">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-04-09T11:20:00.000-05:00">DRAFT</status_change>
            <status_change date="2007-04-25T19:52:21.584-04:00">INTERIM</status_change>
            <modified comment="Dropped tst:4078 in favor of existing tst:3019." date="2007-04-26T13:47:00.955-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-05-23T15:05:34.661-04:00">ACCEPTED</status_change>
            <modified comment="Changed the CPE reference" date="2008-04-04T11:17:00.742-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2008-04-04T11:25:17.766-04:00">INTERIM</status_change>
            <status_change date="2008-04-21T04:00:15.390-04:00">ACCEPTED</status_change>
            <modified comment="Changed the tests for x86, SP2, and windows to be case insensitive and replaced the test for Windows 5.2 with a new test for 2003" date="2009-12-02T16:05:00.749-04:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <status_change date="2009-12-02T16:05:00.749-04:00">INTERIM</status_change>
            <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:56:00.085-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <modified comment="Updating regex to include parenthesis" date="2009-12-08T17:31:00.354-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <status_change date="2010-01-04T04:01:28.375-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1935 - Updated Windows 2003 Server CPE names." date="2011-03-29T13:48:00.699-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-03-29T13:51:28.652-04:00">INTERIM</status_change>
            <status_change date="2011-04-18T04:00:35.900-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:44:01.374-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:02:08.090-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1935 - Modifications vary from minor OVAL title/description changes to suggesting an alternative CPE name to use." date="2011-09-28T11:29:00.976-04:00">
              <contributor organization="The MITRE Corporation">David Rothenberg</contributor>
            </modified>
            <status_change date="2011-09-28T11:33:27.913-04:00">INTERIM</status_change>
            <status_change date="2011-10-17T04:00:14.602-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criterion comment="Windows Server 2003 is installed" test_ref="oval:org.mitre.oval:tst:11145"/>
        <criterion comment="a version of Windows for the x86 architecture is installed" test_ref="oval:org.mitre.oval:tst:3823"/>
        <criterion comment="Win2K/XP/2003/Vista/2008 service pack 2 is installed" test_ref="oval:org.mitre.oval:tst:3019"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1082" version="1" class="vulnerability">
      <metadata>
        <title>Exchange 2000 Server TNEF Decoding Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Outlook</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0002" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0002"/>
        <description>Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-11T12:56:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-12T09:21:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-01T09:08:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the version of Mapi32.dll is greater than or equal 6.0.6603.0 (Exchange 2000 Server,SP3 is installed)" negate="false" test_ref="oval:org.mitre.oval:tst:1182"/>
        <criterion comment="the version of Mapi32.dll is less than 6.0.6617.47" negate="false" test_ref="oval:org.mitre.oval:tst:1181"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1079" version="3" class="vulnerability">
      <metadata>
        <title>MS CIFS Spoofed Browse Frame Request Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>NetBIOS</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2000-1079" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-1079"/>
        <description>Interactions between the CIFS Browser Protocol and NetBIOS as implemented in Microsoft Windows 95, 98, NT, and 2000 allow remote attackers to modify dynamic NetBIOS name cache entries via a spoofed Browse Frame Request in a unicast or UDP broadcast datagram.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-01-13T12:00:00.000-04:00" comment="modified wrt-398 - corrected regular expression on key. needed to escape all back slashes">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2005-01-20T01:23:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Removed reference to test for nt 4.0 and add reference to nt 4.0 inventory definition." date="2008-02-28T12:48:00.621-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2008-03-03T04:00:30.803-05:00">INTERIM</status_change>
            <status_change date="2008-03-24T04:00:12.413-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Software section">
          <criteria operator="OR" comment="Windows 95, 98, NT or 2000 is installed">
            <criterion comment="Windows 95 or 98 Installed" test_ref="oval:org.mitre.oval:tst:1186"/>
            <criteria operator="OR" comment="Windows NT or 2000 Installed">
              <extend_definition comment="Microsoft Windows NT is installed" definition_ref="oval:org.mitre.oval:def:36"/>
              <criterion comment="Windows 2000 is installed" test_ref="oval:org.mitre.oval:tst:3085"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Configuration section">
          <criterion comment="TCP/IP NetBIOS not disabled" test_ref="oval:org.mitre.oval:tst:1185"/>
          <criterion comment="WINS Client binding not disabled" test_ref="oval:org.mitre.oval:tst:1184"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1076" version="2" class="vulnerability">
      <metadata>
        <title>Windows NT/2000 ASN.1 Library Double-free Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft ASN.1 Library</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0123" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0123"/>
        <description>Double free vulnerability in the ASN.1 library as used in Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service and possibly execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Removed reference to test for nt 4.0 and add reference to nt 4.0 inventory definition." date="2008-02-28T12:48:00.621-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2008-03-03T04:00:30.387-05:00">INTERIM</status_change>
            <status_change date="2008-03-24T04:00:11.998-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Software section">
        <criteria operator="OR" comment="Windows NT or 2000 is installed">
          <extend_definition comment="Microsoft Windows NT is installed" definition_ref="oval:org.mitre.oval:def:36"/>
          <criterion comment="Windows 2000 is installed" test_ref="oval:org.mitre.oval:tst:3085"/>
        </criteria>
        <criterion comment="the version of msasn1.dll is less than 5.0.2195.6905" test_ref="oval:org.mitre.oval:tst:1190"/>
        <criterion negate="true" comment="the patch kb835732 is installed" test_ref="oval:org.mitre.oval:tst:1510"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:36" version="6" class="inventory">
      <metadata>
        <title>Microsoft Windows NT is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_nt"/>
        <description>The operating system installed on the system is Microsoft Windows NT.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-26T12:55:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2006-06-26T12:55:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added CPE reference." date="2007-04-30T07:48:00.621-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-30T08:04:19.640-04:00">INTERIM</status_change>
            <status_change date="2007-05-23T15:05:44.870-04:00">ACCEPTED</status_change>
            <modified comment="Removed reference to test for nt 4.0 and add reference to nt 4.0 inventory definition." date="2008-02-28T12:48:00.621-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Removed datatype attribute from the value element of the registry state." date="2008-02-28T14:05:00.268-05:00">
              <contributor organization="Hewlett-Packard">Jeff Cheng</contributor>
            </modified>
            <status_change date="2008-02-28T14:07:43.712-05:00">INTERIM</status_change>
            <status_change date="2008-03-17T04:00:20.911-04:00">ACCEPTED</status_change>
            <modified comment="Changed the CPE reference" date="2008-04-04T11:17:00.580-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2008-04-04T11:26:38.604-04:00">INTERIM</status_change>
            <status_change date="2008-04-21T04:00:18.502-04:00">ACCEPTED</status_change>
            <modified comment="Changed the test for windows to be case insensitive" date="2009-12-02T16:05:00.749-04:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <status_change date="2009-12-02T16:05:00.749-04:00">INTERIM</status_change>
            <status_change date="2009-12-21T04:00:30.408-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criterion comment="Windows NT 4.0 is installed" test_ref="oval:org.mitre.oval:tst:3089"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1068" version="7" class="vulnerability">
      <metadata>
        <title>Windows 2000 Internet Printing ISAPI Extension Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0241" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0241"/>
        <description>Buffer overflow in Internet Printing ISAPI extension in Windows 2000 allows remote attackers to gain root privileges via a long print request that is passed to the extension through IIS 5.0.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-01-14T12:00:00.000-04:00" comment="modified wft-340 - added .dll to end of literal string as needed">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-01-20T01:23:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Multiple corrections and update to POSIX compatibility for ste:2656" date="2010-11-29T16:12:00.873-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-11-29T16:13:01.486-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:07.778-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:46:01.877-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:00:15.997-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="File %windir%\System32\Msw3prt.dll is less than 5.0.2195.2956" negate="false" test_ref="oval:org.mitre.oval:tst:1205"/>
        <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1067" version="5" class="vulnerability">
      <metadata>
        <title>Microsoft JScript Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1313" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1313"/>
        <description>Microsoft JScript 5.1, 5.5, and 5.6 on Windows 2000 SP4, and 5.6 on Windows XP, Server 2003, Windows 98 and Windows Me, will "release objects early" in certain cases, which results in memory corruption and allows remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:11.115-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:14:58.565-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1067 - Consolidated criteria for def:1067, 1644, 1785, and 2003." date="2011-01-13T14:04:00.159-05:00">
              <contributor organization="The MITRE Corporation">Nate Przybyszewski</contributor>
            </modified>
            <status_change date="2011-01-13T14:14:01.378-05:00">INTERIM</status_change>
            <status_change date="2011-01-31T04:00:03.086-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1067 - Fixed Definitions with missing platforms." date="2012-12-12T17:14:00.907-05:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-12-12T17:21:12.787-05:00">INTERIM</status_change>
            <status_change date="2012-12-31T04:00:05.397-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Software section">
          <criterion comment="the version of Jscript.dll is greater than or equal to 5.5.0.0" test_ref="oval:org.mitre.oval:tst:42119"/>
          <criterion comment="the version of Jscript.dll is less than 5.6.0.8831" test_ref="oval:org.mitre.oval:tst:1206"/>
        </criteria>
        <criterion comment="the version of Jscript.dll is less than 5.1.0.12512" test_ref="oval:org.mitre.oval:tst:792"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1063" version="6" class="vulnerability">
      <metadata>
        <title>WMF Rendering Code Execution Vulnerability (Windows 2000)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2123" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2123"/>
        <description>Multiple integer overflows in the Graphics Rendering Engine (GDI32.DLL) in Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allow remote attackers to execute arbitrary code via crafted Windows Metafile (WMF) and Enhanced Metafile (EMF) format images that lead to heap-based buffer overflows, as demonstrated using MRBP16::bCheckRecord.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-09T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-11-10T07:06:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-16T01:04:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed regex in ste:2889.  Implemented by Matthew Wojcik." date="2007-03-06T18:19:00.507-05:00">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2007-03-06T18:21:14.349-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:16:39.889-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1063 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:06:47.901-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:00:15.176-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criteria operator="OR" comment="version of Gdi32.dll is less than 5.0.2195.7069 OR the version of Mf3216.dll is less than 5.0.2195.6898">
          <criterion comment="the version of Gdi32.dll is less than 5.0.2195.7069" test_ref="oval:org.mitre.oval:tst:1227"/>
          <criterion comment="the version of mf3216.dll is less than 5.0.2195.6898" test_ref="oval:org.mitre.oval:tst:1398"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1062" version="1" class="vulnerability">
      <metadata>
        <title>DCOM RPC Object Identity Windows 2000 Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Remote Procedure Call (RPC)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0124" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0124"/>
        <description>The DCOM RPC interface for Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause network communications via an "alter context" call that contains additional data, aka the "Object Identity Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="the version of comsvcs.dll is less than 2000.2.3511.0" negate="false" test_ref="oval:org.mitre.oval:tst:1228"/>
        <criterion comment="the patch kb828741 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1499"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1058" version="2" class="vulnerability">
      <metadata>
        <title>Vulnerability in Vector Markup Language (VML) Could Allow Remote Code Execution</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0024" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0024"/>
        <description>Integer overflow in the Vector Markup Language (VML) implementation (vgx.dll) in Microsoft Internet Explorer 5.01, 6, and 7 on Windows 2000 SP4, XP SP2, Server 2003, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted web page that contains unspecified integer properties that cause insufficient memory allocation and trigger a buffer overflow, aka the "VML Buffer Overrun Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2007-01-09T06:00:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-01-11T15:30:00-04:00">DRAFT</status_change>
            <status_change date="2007-02-20T13:39:29.075-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:16:39.546-04:00">ACCEPTED</status_change>
            <modified comment="References registry value for Common Files directory due to multilingual support" date="2008-04-14T11:07:00.466-04:00">
              <contributor organization="GFI Software">Clifford Farrugia</contributor>
            </modified>
            <status_change date="2008-04-14T12:28:16.889-04:00">INTERIM</status_change>
            <status_change date="2008-05-05T04:00:07.621-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Windows Server 2003 Gold or Windows Server 2003 SP1 with IE 6" operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
            <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          </criteria>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="version of Vgx.dll is less than 6.0.3790.623" negate="false" test_ref="oval:org.mitre.oval:tst:181"/>
        </criteria>
        <criteria comment="Windows Server 2003 Gold or Windows Server 2003 with IE 7" operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
            <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          </criteria>
          <extend_definition comment="Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="version of Vgx.dll is less than 7.0.6000.16386" negate="false" test_ref="oval:org.mitre.oval:tst:183"/>
        </criteria>
        <criteria comment="Windows XP SP2 with Internet Explorer 7" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="version of Vgx.dll is less than 7.0.6000.16386" negate="false" test_ref="oval:org.mitre.oval:tst:183"/>
        </criteria>
        <criteria comment="Windows XP SP2 with Internet Explorer 6" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="version of Vgx.dll is less than 6.0.2900.3051" negate="false" test_ref="oval:org.mitre.oval:tst:185"/>
        </criteria>
        <criteria comment="Windows XP (64-bit,SP1) with Internet Explorer 6" operator="AND">
          <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="version of Vgx.dll is less than 6.0.3790.2851" negate="false" test_ref="oval:org.mitre.oval:tst:187"/>
        </criteria>
        <criteria comment="Windows 2000 SP4 with Internet Explorer 6" operator="AND">
          <extend_definition comment="Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="version of Vgx.dll is less than 6.0.2800.1588" negate="false" test_ref="oval:org.mitre.oval:tst:189"/>
        </criteria>
        <criteria comment="Windows 2000 SP4 with Internet Explorer 5.01" operator="AND">
          <extend_definition comment="Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Internet Explorer 5.01, SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="version of Vgx.dll is less than 6.0.2800.1588" negate="false" test_ref="oval:org.mitre.oval:tst:189"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:627" version="6" class="inventory">
      <metadata>
        <title>Microsoft Internet Explorer 7 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Internet Explorer 7</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:ie:7"/>
        <description>A version of Microsoft Internet Explorer 7 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-01-09T06:00:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-01-11T15:30:00-04:00">DRAFT</status_change>
            <status_change date="2007-02-20T13:40:49.320-05:00">INTERIM</status_change>
            <modified comment="Added Microsoft Windows Vista to the list of affected platforms." date="2007-03-05T09:10:00.104-05:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2007-03-21T16:17:23.092-04:00">ACCEPTED</status_change>
            <modified comment="Added Microsoft Internet Explorer 7 product. Removed Microsoft reference" date="2009-06-01T16:05:28.035-04:00">
              <contributor organization="The MITRE Corporation">Brendan Miles</contributor>
            </modified>
            <status_change date="2009-06-08T04:01:04.886-04:00">INTERIM</status_change>
            <status_change date="2009-06-29T04:01:07.843-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:47.971-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:24.527-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:115 - pattern match update for IE 7 inventory def (replaced the greedy pattern" date="2015-02-16T13:23:00.322-05:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2015-02-16T13:25:05.019-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:53.613-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Internet Explorer 7 is installed" test_ref="oval:org.mitre.oval:tst:178"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1055" version="1" class="vulnerability">
      <metadata>
        <title>Windows Address Book Contact Record Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Outlook Express</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2386" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2386"/>
        <description>Unspecified vulnerability in Microsoft Outlook Express 6 and earlier allows remote attackers to execute arbitrary code via a crafted contact record in a Windows Address Book (WAB) file.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-12-13T08:17:04">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-12-14T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:53:47.933-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:28.558-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Win2K,SP4" operator="AND">
          <extend_definition comment="Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Outlook Express 5.5, SP2 is installed" definition_ref="oval:org.mitre.oval:def:504"/>
          <criterion comment="the version of inetcomm.dll is less than 5.50.4971.600" test_ref="oval:org.mitre.oval:tst:134"/>
        </criteria>
        <criteria comment="WinXP,SP2" operator="AND">
          <extend_definition comment="Windows 2000 SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Microsoft Outlook Express 6, SP1 is installed" definition_ref="oval:org.mitre.oval:def:488"/>
          <criterion comment="the version of inetcomm.dll is less than 6.0.2800.1896" test_ref="oval:org.mitre.oval:tst:143"/>
        </criteria>
        <criteria comment="WinXP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Microsoft Outlook Express 6 for Windows XP is installed" definition_ref="oval:org.mitre.oval:def:208"/>
          <criterion comment="the version of inetcomm.dll is less than 6.0.2900.3028" test_ref="oval:org.mitre.oval:tst:145"/>
        </criteria>
        <criteria comment="WinXP,SP1 (64-bit)" operator="AND">
          <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <extend_definition comment="Microsoft Outlook Express 6 for Windows XP is installed" definition_ref="oval:org.mitre.oval:def:208"/>
          <criterion comment="the version of inetcomm.dll is less than 6.0.3790.2826" test_ref="oval:org.mitre.oval:tst:146"/>
        </criteria>
        <criteria comment="S03-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <extend_definition comment="Microsoft Outlook Express 6 for Windows XP is installed" definition_ref="oval:org.mitre.oval:def:208"/>
          <criterion comment="the version of inetcomm.dll is less than 6.0.3790.607" test_ref="oval:org.mitre.oval:tst:148"/>
        </criteria>
        <criteria comment="S03,SP1" operator="AND">
          <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <extend_definition comment="Microsoft Outlook Express 6 for Windows XP is installed" definition_ref="oval:org.mitre.oval:def:208"/>
          <criterion comment="the version of inetcomm.dll is less than 6.0.3790.2826" test_ref="oval:org.mitre.oval:tst:146"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:504" version="3" class="inventory">
      <metadata>
        <title>Microsoft Outlook Express 5.5 SP2 is installed.</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Outlook Express 5.5</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:outlook_express:5.5:sp2"/>
        <description>Microsoft Outlook Express 5.5 SP2 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-12-13T08:17:04">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-12-14T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:53:59.147-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:41.385-05:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:06.259-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:06.259-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:03.428-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Microsoft Outlook Express 5.5 SP2 is installed" test_ref="oval:org.mitre.oval:tst:1514"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:488" version="3" class="inventory">
      <metadata>
        <title>Microsoft Outlook Express 6 SP1 is installed.</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Outlook Express 6</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:outlook_express:6.00.2800.1106"/>
        <description>Microsoft Outlook Express 6 SP1 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-12-13T08:17:04">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-12-14T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:53:58.863-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:38.525-05:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:06.259-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:06.259-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:03.141-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Microsoft Outlook Express 6 SP1 is installed" test_ref="oval:org.mitre.oval:tst:1355"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:208" version="8" class="inventory">
      <metadata>
        <title>Microsoft Outlook Express 6.0 for Windows XP/2003 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Outlook Express 6.0</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:outlook_express:6.0"/>
        <description>Microsoft Outlook Express 6.0 for Windows XP/2003 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-03T12:32:22">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-07-03T14:04:49.139-04:00">DRAFT</status_change>
            <status_change date="2007-07-18T15:57:53.037-04:00">INTERIM</status_change>
            <status_change date="2007-08-02T14:47:15.591-04:00">ACCEPTED</status_change>
            <modified date="2009-06-15T04:44:54" comment="Added CPE">
              <contributor organization="The MITRE Corporation">Brendan Miles</contributor>
            </modified>
            <status_change date="2009-06-22T04:00:51.618-04:00">INTERIM</status_change>
            <status_change date="2009-07-13T04:00:31.131-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:1485 - Correction to pattern match in ste:1485." date="2010-12-27T19:49:00.448-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <status_change date="2010-12-27T19:58:09.275-05:00">INTERIM</status_change>
            <status_change date="2011-01-17T04:00:19.196-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:208 - Modifications vary from minor OVAL title/description changes to suggesting an alternative CPE name to use." date="2011-09-28T11:29:00.976-04:00">
              <contributor organization="The MITRE Corporation">David Rothenberg</contributor>
            </modified>
            <status_change date="2011-09-28T11:33:18.675-04:00">INTERIM</status_change>
            <status_change date="2011-10-17T04:00:15.525-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:06.259-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:06.259-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:02:59.974-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Windows XP is installed" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Microsoft Outlook Express 6 for Windows XP/2003 is installed" test_ref="oval:org.mitre.oval:tst:1633"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1052" version="1" class="vulnerability">
      <metadata>
        <title>Multiple Vulnerabilities in Rockliffe MailSite Express</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Rockliffe MailSite Express</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3428" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3428"/>
        <description>Cross-site scripting (XSS) vulnerability in Rockliffe MailSite Express before 6.1.22 allows remote attackers to inject arbitrary web script or HTML via a message body.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-25T07:14:00.000-04:00">
              <contributor organization="OS2A">Rahul Mohandas</contributor>
            </submitted>
            <status_change date="2006-01-25T07:30:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the software MailSite Express version 6.1.20 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1239"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1051" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 IIS Directory Traversal Command Execution (Test 2)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0333" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0333"/>
        <description>Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. (dot dot) and "\" characters twice.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="File %windir%\System32\msw3prt.dll is less than 5.0.2195.3649" negate="false" test_ref="oval:org.mitre.oval:tst:1240"/>
        <criterion comment="Patch Q293826 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3020"/>
        <criterion comment="Patch Q301625 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3037"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1047" version="3" class="vulnerability">
      <metadata>
        <title>SNMP Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5583" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5583"/>
        <description>Buffer overflow in the SNMP Service in Microsoft Windows 2000 SP4, XP SP2, Server 2003, Server 2003 SP1, and possibly other versions allows remote attackers to execute arbitrary code via a crafted SNMP packet, aka "SNMP Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-12-13T08:17:04">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-12-14T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:53:47.448-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:27.768-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1047 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:06:21.914-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:00:03.324-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win2K,SP4">
          <extend_definition comment="Microsoft Windows 2000 SP4 or later is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of snmp.exe is less than 5.0.2195.7112" test_ref="oval:org.mitre.oval:tst:118"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP2">
          <extend_definition comment="Microsoft Windows XP SP2 or later is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of snmp.exe is less than 5.1.2600.3038" test_ref="oval:org.mitre.oval:tst:119"/>
        </criteria>
        <criteria operator="AND" comment="WinXP,SP1 (64-bit)">
          <extend_definition comment="Microsoft Windows XP SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="the version of snmp.exe is less than 5.2.3790.2837" test_ref="oval:org.mitre.oval:tst:120"/>
        </criteria>
        <criteria operator="AND" comment="S03-Gold">
          <extend_definition comment="Microsoft Windows Server 2003 (x86) Gold is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="the version of snmp.exe is less than 5.2.3790.615" test_ref="oval:org.mitre.oval:tst:121"/>
        </criteria>
        <criteria operator="AND" comment="S03,SP1">
          <extend_definition comment="Microsoft Windows Server 2003 SP1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of snmp.exe is less than 5.2.3790.2837" test_ref="oval:org.mitre.oval:tst:120"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1046" version="1" class="vulnerability">
      <metadata>
        <title>Windows Utility Manager Shatter Message Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Utility Manager</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0908" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0908"/>
        <description>The Utility Manager in Microsoft Windows 2000 executes winhlp32.exe with system privileges, which allows local users to execute arbitrary code via a "Shatter" style attack using a Windows message that accesses the context sensitive help button in the GUI, as demonstrated using the File Open dialog in the Help window, a different vulnerability than CVE-2004-0213.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="the version of umandlg.dll is less than 1.0.0.4" negate="false" test_ref="oval:org.mitre.oval:tst:1244"/>
        <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1045" version="4" class="vulnerability">
      <metadata>
        <title>Windows 2000 Print Spooler Service Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Print Spooler Service</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1984" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1984"/>
        <description>Buffer overflow in the Print Spooler service (Spoolsv.exe) for Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via a malicious message.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-09-19T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:49.329-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:00:12.594-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="Win2K/XP/2003 service pack 4 (or earlier) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1247"/>
        <criterion comment="the version of Spoolsv.exe is less than 5.0.2195.7059" negate="false" test_ref="oval:org.mitre.oval:tst:1246"/>
        <criterion comment="the patch KB896423 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1245"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:104" class="vulnerability" version="1">
      <metadata>
        <title>Microsoft XML Core Services Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft XML Core Services</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5745" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5745"/>
        <description>Unspecified vulnerability in the setRequestHeader method in the XMLHTTP (XML HTTP) ActiveX Control 4.0 in Microsoft XML Core Services 4.0 on Windows, when accessed by Internet Explorer, allows remote attackers to execute arbitrary code via crafted arguments that lead to memory corruption, a different vulnerability than CVE-2006-4685.  NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-11-15T12:28:05">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-11-17T12:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:53:47.020-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:27.419-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="Microsoft XML Core Services 4 is installed" definition_ref="oval:org.mitre.oval:def:1002"/>
          <criterion comment="The version of Msxml4.dll is less than 4.20.9841.0" negate="false" test_ref="oval:org.mitre.oval:tst:62"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft XML Core Services 6 is installed" definition_ref="oval:org.mitre.oval:def:454"/>
          <criterion comment="The version of Msxml6.dll is less than 6.0.3890.0" negate="false" test_ref="oval:org.mitre.oval:tst:138"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:454" version="3" class="inventory">
      <metadata>
        <title>Microsoft XML Core Services 6 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft XML Core Services 6</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:xml_core_services:6"/>
        <description>Microsoft XML Core Services 6 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-10-11T05:29:41">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-13T14:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-31T19:35:42.283-05:00">INTERIM</status_change>
            <status_change date="2006-11-21T21:27:51.747-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:454 - products added to inventories" date="2015-04-17T09:39:00.289-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-04-17T09:41:23.422-04:00">INTERIM</status_change>
            <status_change date="2015-05-04T04:00:19.661-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Microsoft XML Core Services 6 is installed." test_ref="oval:org.mitre.oval:tst:182"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1002" version="3" class="inventory">
      <metadata>
        <title>Microsoft XML Core Services 4 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft XML Core Services 4</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:xml_core_services:4"/>
        <description>Microsoft XML Core Services 4 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-10-11T05:29:41">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-13T14:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-31T19:35:29.444-05:00">INTERIM</status_change>
            <status_change date="2006-11-21T21:27:39.227-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1002 - products added to inventories" date="2015-04-17T09:39:00.289-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-04-17T09:41:23.144-04:00">INTERIM</status_change>
            <status_change date="2015-05-04T04:00:06.387-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Microsoft XML Core Services 4 is installed." test_ref="oval:org.mitre.oval:tst:30"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1037" version="3" class="vulnerability">
      <metadata>
        <title>Mozilla Privilege Escalation via XBL.method.eval</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1735" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1735"/>
        <description>Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to execute arbitrary code by using an eval in an XBL method binding (XBL.method.eval) to create Javascript functions that are compiled with extra privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-07T09:05:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:10.798-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:1133" date="2007-02-26T08:08:00.208-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-26T08:09:15.419-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:1135" date="2007-02-26T08:21:00.993-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:1136" date="2007-02-26T08:24:00.848-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:1138" date="2007-02-26T08:25:00.405-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:2283" date="2007-02-26T08:29:00.407-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:2284" date="2007-02-26T08:30:00.724-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:39.048-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:881" date="2007-04-23T12:05:00.811-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:12:53.554-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:882" date="2007-04-23T12:05:00.939-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in obj:883" date="2007-04-23T12:05:00.804-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in obj:1385" date="2007-04-23T12:05:00.430-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:10:50.515-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1268"/>
          <criterion comment="Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1267"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Thunderbird version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1266"/>
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1265"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.12 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1264"/>
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1263"/>
        </criteria>
        <criteria operator="AND" comment="A pre-release of SeaMonkey 1.0 is installed">
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2439"/>
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2438"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1036" version="1" class="vulnerability">
      <metadata>
        <title>Veritas Backup Exec RestrictAnonymous Forced Misconfiguration Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Veritas Backup Exec 8.5</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1117" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1117"/>
        <description>Veritas Backup Exec 8.5 and earlier requires that the "RestrictAnonymous" registry key for Microsoft Exchange 2000 must be set to 0, which enables anonymous listing of the SAM database and shares.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-15T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-06-30T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-04-08T12:00:00.000-04:00" comment="modified wrt-472 - wrt-472 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Software section">
          <criterion comment="Affected bkupexec.exe versions 3.60.1.298" test_ref="oval:org.mitre.oval:tst:1271"/>
          <criterion comment="Veritas Backup Exec 8.5 Installed" test_ref="oval:org.mitre.oval:tst:1270"/>
        </criteria>
        <criteria operator="AND" comment="Configuration section">
          <criterion comment="RestrictAnonymous registry value allows anonymous connections" test_ref="oval:org.mitre.oval:tst:1269"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1027" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 DirectPlay Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft DirectPlay</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0202" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0202"/>
        <description>IDirectPlay4 Application Programming Interface (API) of Microsoft DirectPlay 7.0a thru 9.0b, as used in Windows Server 2003 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-11T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-06-30T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-12T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criteria operator="OR" comment="Vulnerable versions of DirectX">
          <criteria operator="AND" comment="Unpatched DirectX 7.0">
            <criterion comment="DirectX 7.0x Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1296"/>
            <criterion comment="File %windir%\system32\dplayx.dll version is less than 5.0.2195.6927" negate="false" test_ref="oval:org.mitre.oval:tst:1295"/>
            <criterion comment="Patch Windows2000-KB839643-x86-ENU.EXE Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1294"/>
          </criteria>
          <criteria operator="AND" comment="Unpatched DirectX 8.0x">
            <criterion comment="DirectX 8.0x Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1293"/>
            <criterion comment="File %windir%\system32\dplayx.dll version is less than 5.0.2258.410" negate="false" test_ref="oval:org.mitre.oval:tst:1292"/>
            <criterion comment="Patch DirectX80-KB839643-x86-ENU Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1291"/>
          </criteria>
          <criteria operator="AND" comment="Unpatched DirectX 8.1x">
            <criterion comment="DirectX 8.1x Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1290"/>
            <criterion comment="File %windir%\system32\dplayx.dll version is less than 5.1.2600.891" negate="false" test_ref="oval:org.mitre.oval:tst:1289"/>
            <criterion comment="Patch DirectX81-KB839643-x86-ENU Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1288"/>
          </criteria>
          <criteria operator="AND" comment="Unpatched DirectX 8.2x">
            <criterion comment="DirectX 8.2x Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1287"/>
            <criterion comment="File %windir%\system32\dplayx.dll version is less than 5.2.3677.144" negate="false" test_ref="oval:org.mitre.oval:tst:1286"/>
            <criterion comment="Patch DirectX82-KB839643-x86-ENU Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1285"/>
          </criteria>
          <criteria operator="AND" comment="Unpatched DirectX 9.0x">
            <criterion comment="DirectX 9.0x Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1284"/>
            <criterion comment="File %windir%\system32\dplayx.dll version is less than 5.3.0.903" negate="false" test_ref="oval:org.mitre.oval:tst:1283"/>
            <criterion comment="Patch DirectX90-KB839643-x86-ENU Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1282"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1026" version="4" class="vulnerability">
      <metadata>
        <title>IE5.01,SP3 File Disclosure via Redirects Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0648" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0648"/>
        <description>The legacy &lt;script> data-island capability for XML in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to read arbitrary XML files, and portions of other files, via a URL whose "src" attribute redirects to a local file.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-22T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-06-22T12:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2824. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:48:00.494-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:52:25.100-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:26.475-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:45.064-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:06.804-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3015"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3541.2700" negate="false" test_ref="oval:org.mitre.oval:tst:2751"/>
          <criterion comment="the patch kb883939 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2750"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1016" version="2" class="vulnerability">
      <metadata>
        <title>Win2k Domain Controller LSASS Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Lightweight Directory Access Protocol (LDAP)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0663" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0663"/>
        <description>Unknown vulnerability in the Local Security Authority Subsystem Service (LSASS) in Windows 2000 domain controllers allows remote attackers to cause a denial of service via a crafted LDAP message.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-31T04:13:00.000-04:00" comment="Replaced reference to obj:1374 with reference to obj:1550 since it referencess Product\Options and not ProductOptions in the controlset registry key.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:53:46.187-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 (domain controller) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="this is an NT Server (domain controller)" negate="false" test_ref="oval:org.mitre.oval:tst:3035"/>
        </criteria>
        <criterion comment="the version of lsasrv.dll is less than 5.0.2195.6902" negate="false" test_ref="oval:org.mitre.oval:tst:1511"/>
        <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1014" version="5" class="vulnerability">
      <metadata>
        <title>IE File Download Dialog Deception Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0875" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0875"/>
        <description>Internet Explorer 5.5 and 6.0 allows remote attackers to cause the File Download dialogue box to misrepresent the name of the file in the dialogue in a way that could fool users into thinking that the file type is safe to download.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-29T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-05-25T04:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T04:00:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2004-09-22T04:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-09-22T04:01:00.000-04:00" comment="Replaced IE cumulative patch IDs to correspond to the original IDs">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2004-10-06T04:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Changed IE registry test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:39.294-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:06.476-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="the version of mshtml.dll is less than 6.0.2712.0300" negate="false" test_ref="oval:org.mitre.oval:tst:1460"/>
          <criterion comment="Patch Q313675 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1459"/>
          <criterion comment="Patch Q316059.exe Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1458"/>
          <criterion comment="Patch Q319282 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1457"/>
          <criterion comment="the patch q321232 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3119"/>
          <criterion comment="the patch q323759 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3118"/>
          <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
          <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
          <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
          <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
          <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
          <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
          <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
          <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
          <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="File Downloads Not Disabled">
            <criterion comment="Use Machine Settings" negate="false" test_ref="oval:org.mitre.oval:tst:1456"/>
            <criterion comment="File Downloads Allowed In At Least One Zone" negate="false" test_ref="oval:org.mitre.oval:tst:1455"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1011" version="2" class="vulnerability">
      <metadata>
        <title>Windows 2000 IIS5 WebDAV Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1182" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1182"/>
        <description>IIS 5.0 and 5.1 allows remote attackers to cause a denial of service (crash) via malformed WebDAV requests that cause a large amount of memory to be assigned.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-01-11T12:00:00.000-04:00" comment="modified wft-330 - changed the version of msw3prt.dll to test against from 5.5.2195.58075 to 5.0.2195.5807">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-01-20T01:18:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="File %windir%\System32\msw3prt.dll is less than 5.0.2195.5807" negate="false" test_ref="oval:org.mitre.oval:tst:1447"/>
        <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
        <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1010" version="1" class="vulnerability">
      <metadata>
        <title>Microsoft Outlook Express v6.0,SP1 MHTML URL Processing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Outlook Express</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0380" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0380"/>
        <description>The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through Outlook Express 6 SP1 allows remote attackers to bypass domain restrictions and execute arbitrary code, as demonstrated on Internet Explorer using script in a compiled help (CHM) file that references the InfoTech Storage (ITS) protocol handlers such as (1) ms-its, (2) ms-itss, (3) its, or (4) mk:@MSITStore, aka the "MHTML URL Processing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Microsoft Outlook Express 6 SP1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1355"/>
        <criterion comment="the version of inetcomm.dll is less than 6.00.2800.1409" negate="false" test_ref="oval:org.mitre.oval:tst:1319"/>
        <criterion comment="the patch kb837009 is installed (installed components key)" negate="true" test_ref="oval:org.mitre.oval:tst:1512"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1005" version="5" class="vulnerability">
      <metadata>
        <title>IE6,SP1 DHTML Method Heap Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0055" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0055"/>
        <description>Internet Explorer 5.01, 5.5, and 6 does not properly validate buffers when handling certain DHTML methods including the createControlRange Javascript function, which allows remote attackers to execute arbitrary code, aka the "DHTML Method Heap Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-03-23T08:09:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-13T12:15:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-05-04T12:33:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed test to check kb867282.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:2735. Set version element datatype to version. Implemented by Jon Baker of The MITRE Corporation." date="2007-01-13T19:44:00.916-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-01-13T19:45:56.706-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:26.141-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:247 - cvename in reference was replaced with CVE-2013-1311 and description was modified" date="2014-02-04T12:25:00.319-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-04T12:28:40.828-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:06.150-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criteria operator="OR" comment="a vulnerable version of mshtml.dll exisits GDR/QFE">
            <criterion comment="machine has followed the GDR update path and mshtml.dll is less than 6.0.2800.1491" negate="false" test_ref="oval:org.mitre.oval:tst:1329"/>
            <criterion comment="machine has followed the QFE update path and mshtml.dll is less than 6.0.2800.1492" negate="false" test_ref="oval:org.mitre.oval:tst:1328"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100107" version="2" class="vulnerability">
      <metadata>
        <title>Firefox and Mozilla top.focus() Cross-Site Scripting Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2266" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2266"/>
        <description>Firefox before 1.0.5 and Mozilla before 1.7.9 allows a child frame to call top.focus and other methods in a parent frame, even when the parent is in a different domain, which violates the same origin policy and allows remote attackers to steal sensitive information such as cookies and passwords from web sites whose child frames do not verify that they are in the same domain as their parents.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T04:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <modified date="2005-09-07T04:00:00.000-04:00" comment="Added description">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-09-19T04:05:00.000-04:00" comment="modified wrt-10048 - Removed extra \\ in key">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2005-10-12T05:49:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed ste:259: Added beginning anchors to regular expression in pattern match, to avoid mid-string matches." date="2007-01-22T01:46:00.843-05:00">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2007-01-22T01:50:42.494-05:00">INTERIM</status_change>
            <modified comment="Fixed ste:261: Added beginning anchors to the regular expression used in the pattern match, to avoid mid-string matches." date="2007-01-22T01:50:00.388-05:00">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2007-02-20T13:39:25.841-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criterion comment="Firefox version 1.0.4 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:263"/>
        <criterion comment="Mozilla Suite version 1.7.8 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:261"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100096" version="6" class="vulnerability">
      <metadata>
        <title>Windows 2000 PKINIT Information Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1982" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1982"/>
        <description>Unknown vulnerability in the PKINIT Protocol for Microsoft Windows 2000, Windows XP, and Windows Server 2003 could allow a local user to obtain information and spoof a server via a man-in-the-middle (MITM) attack between a client and a domain controller when PKINIT smart card authentication is being used.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed regex in ste:2889.  Implemented by Matthew Wojcik." date="2007-03-06T18:19:00.507-05:00">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2007-03-06T18:21:06.969-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:16:38.194-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:100096 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:06:14.198-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:00:05.891-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="the version of kerberos.dll is less than 5.0.2195.7053" test_ref="oval:org.mitre.oval:tst:222"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100095" version="6" class="vulnerability">
      <metadata>
        <title>Windows 2000 Kerberos Message DoS Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1981" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1981"/>
        <description>Unknown vulnerability in Microsoft Windows 2000 Server and Windows Server 2003 domain controllers allows remote authenticated users to cause a denial of service (system crash) via a crafted Kerberos message.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed regex in ste:2889.  Implemented by Matthew Wojcik." date="2007-03-06T18:19:00.507-05:00">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2007-03-06T18:21:06.415-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:16:37.938-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:100095 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:06:12.210-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:00:05.520-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="the version of kerberos.dll is less than 5.0.2195.7053" test_ref="oval:org.mitre.oval:tst:222"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100057" version="4" class="vulnerability">
      <metadata>
        <title>Mozilla Local File Loading Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0141" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0141"/>
        <description>Firefox before 1.0 and Mozilla before 1.7.5 allow remote attackers to load local files via links "with a custom getter and toString method" that are middle-clicked by the user to be opened in a new tab.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:240" date="2007-02-12T10:21:00.419-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-12T10:23:01.237-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:241" date="2007-02-12T13:51:00.885-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:232" date="2007-02-12T13:56:00.878-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:233" date="2007-02-12T13:58:00.347-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:37.640-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:234" date="2007-04-23T12:05:00.430-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:05:56.962-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:229" date="2007-04-23T12:05:00.501-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:10:50.239-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 0.9 or earlier is installed">
          <criterion comment="Firefox version 0.9 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:243"/>
          <criterion comment="Mozilla Firefox version 0.9 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:242"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.4 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.4 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:235"/>
          <criterion comment="Mozilla Suite version 1.7.4 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:234"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100056" version="4" class="vulnerability">
      <metadata>
        <title>Mozilla Creates World-readable temp Files</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0142" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0142"/>
        <description>Firefox 0.9, Thunderbird 0.6 and other versions before 0.9, and Mozilla 1.7 before 1.7.5 save temporary files with world-readable permissions, which allows local users to read certain web content or attachments that belong to other users, e.g. content that is managed by helper applications such as PDF.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T04:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <modified date="2005-09-19T04:00:00.000-04:00" comment="modified wrt-10060 - Removed extra \\ in key">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2005-10-05T11:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-26T06:46:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:236" date="2007-02-12T13:53:00.146-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-12T13:53:51.272-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:237" date="2007-02-12T13:55:00.760-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:228" date="2007-02-12T13:59:00.387-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:229" date="2007-02-12T14:00:00.680-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:230" date="2007-02-12T13:54:00.993-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:231" date="2007-02-26T08:05:00.981-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:37.316-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:232" date="2007-04-23T12:05:00.713-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:07:01.823-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:225" date="2007-04-23T12:05:00.147-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in obj:227" date="2007-04-23T12:05:00.984-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:10:49.901-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Suite version 1.7-1.7.3 is installed">
          <criterion comment="Mozilla Suite version 1.7-1.7.3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:239"/>
          <criterion comment="Mozilla Suite version 1.7-1.7.3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:238"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Firefox version 0.9 is installed">
          <criterion comment="Firefox version 0.9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:233"/>
          <criterion comment="Mozilla Firefox version 0.9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:232"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Thunderbird version 0.6-0.8 is installed">
          <criterion comment="Mozilla Thunderbird version 0.6-0.8 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:231"/>
          <criterion comment="Mozilla Thunderbird version 0.6-0.8 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:230"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100055" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla SSL Lock Image Spoofing during Binary Download</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0143" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0143"/>
        <description>Firefox before 1.0 and Mozilla before 1.7.5 display the SSL lock icon when an insecure page loads a binary file from a trusted site, which could facilitate phishing attacks.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:55:00.000-04:00" comment="Added Firefox, Mozilla as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:240" date="2007-02-12T10:21:00.419-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-12T10:23:01.697-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:241" date="2007-02-12T13:51:00.885-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:232" date="2007-02-12T13:56:00.878-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:233" date="2007-02-12T13:58:00.347-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:36.921-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:234" date="2007-04-23T12:05:00.430-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:05:57.981-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:229" date="2007-04-23T12:05:00.501-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:10:49.517-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 0.9 or earlier is installed">
          <criterion comment="Firefox version 0.9 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:243"/>
          <criterion comment="Mozilla Firefox version 0.9 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:242"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.4 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.4 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:235"/>
          <criterion comment="Mozilla Suite version 1.7.4 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:234"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100054" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla SSL Lock Image Spoofing via "View Source"</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0144" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0144"/>
        <description>Firefox before 1.0 and Mozilla before 1.7.5 display the secure site lock icon when a view-source: URL references a secure SSL site while an insecure page is being loaded, which could facilitate phishing attacks.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:54:00.000-04:00" comment="Added Firefox, Mozilla as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:240" date="2007-02-12T10:21:00.419-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-12T10:23:00.566-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:241" date="2007-02-12T13:51:00.885-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:232" date="2007-02-12T13:56:00.878-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:233" date="2007-02-12T13:58:00.347-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:36.561-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:234" date="2007-04-23T12:05:00.430-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:05:55.581-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:229" date="2007-04-23T12:05:00.501-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:10:49.112-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 0.9 or earlier is installed">
          <criterion comment="Firefox version 0.9 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:243"/>
          <criterion comment="Mozilla Firefox version 0.9 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:242"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.4 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.4 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:235"/>
          <criterion comment="Mozilla Suite version 1.7.4 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:234"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100053" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Inactive Tab Form Data Theft Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1381" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1381"/>
        <description>Firefox before 1.0 and Mozilla before 1.7.5 allow inactive (background) tabs to focus on input being entered in the active tab, as originally reported using form fields, which allows remote attackers to steal sensitive data that is intended for other sites, which could facilitate phishing attacks.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:52:00.000-04:00" comment="Added Firefox, Mozilla as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:240" date="2007-02-12T10:21:00.419-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-12T10:23:01.978-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:241" date="2007-02-12T13:51:00.885-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:232" date="2007-02-12T13:56:00.878-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:233" date="2007-02-12T13:58:00.347-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:36.128-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:234" date="2007-04-23T12:05:00.430-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:05:58.446-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:229" date="2007-04-23T12:05:00.501-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:10:48.772-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 0.9 or earlier is installed">
          <criterion comment="Firefox version 0.9 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:243"/>
          <criterion comment="Mozilla Firefox version 0.9 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:242"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.4 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.4 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:235"/>
          <criterion comment="Mozilla Suite version 1.7.4 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:234"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100052" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Malicious news: Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Mozilla Thunderbird</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1316" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1316"/>
        <description>Heap-based buffer overflow in MSG_UnEscapeSearchUrl in nsNNTPProtocol.cpp for Mozilla 1.7.3 and earlier allows remote attackers to cause a denial of service (application crash) via an NNTP URL (news:) with a trailing '\' (backslash) character, which prevents a string from being NULL terminated.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T04:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Added CVE #">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-10-05T11:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-26T06:46:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:51:00.000-04:00" comment="Added Mozilla, Thunderbird as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:235." date="2007-01-24T21:18:00.747-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-01-24T21:19:13.853-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:234." date="2007-01-24T21:23:00.750-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:232" date="2007-02-12T13:56:00.878-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:233" date="2007-02-12T13:58:00.347-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:35.728-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:231" date="2007-04-23T12:05:00.336-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:08:38.450-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:229" date="2007-04-23T12:05:00.501-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:10:48.341-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Thunderbird version 0.8 or earlier is installed">
          <criterion comment="Mozilla Thunderbird version 0.8 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:237"/>
          <criterion comment="Mozilla Thunderbird version 0.8 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:236"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.4 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.4 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:235"/>
          <criterion comment="Mozilla Suite version 1.7.4 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:234"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100051" version="5" class="vulnerability">
      <metadata>
        <title>Firefox Script-generated Download Prompt Bypass</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0145" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0145"/>
        <description>Firefox before 1.0 does not properly distinguish between user-generated and synthetic click events, which allows remote attackers to use Javascript to bypass the file download prompt when the user uses the Alt-click feature.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:49:00.000-04:00" comment="Added Firefox as affected product.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:240" date="2007-02-12T10:21:00.419-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-12T10:23:01.033-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:241" date="2007-02-12T13:51:00.885-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:35.323-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:234" date="2007-04-23T12:05:00.430-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:05:56.458-04:00">INTERIM</status_change>
            <status_change date="2007-05-09T16:10:48.015-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 0.9 or earlier is installed">
          <criterion comment="Firefox version 0.9 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:243"/>
          <criterion comment="Mozilla Firefox version 0.9 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:242"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100050" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Inactive Tab Dialog Box Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Mozilla Firefox</product>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1380" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1380"/>
        <description>Firefox before 1.0 and Mozilla before 1.7.5 allows inactive (background) tabs to launch dialog boxes, which can allow remote attackers to spoof the dialog boxes from web sites in other windows and facilitate phishing attacks, aka the "Dialog Box Spoofing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:240" date="2007-02-12T10:21:00.419-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-12T10:23:00.822-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:241" date="2007-02-12T13:51:00.885-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:232" date="2007-02-12T13:56:00.878-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:233" date="2007-02-12T13:58:00.347-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:35.026-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:234" date="2007-04-23T12:05:00.430-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:05:56.038-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:229" date="2007-04-23T12:05:00.501-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:10:47.647-04:00">ACCEPTED</status_change>
            <modified comment="Added affected products" date="2007-09-07T16:30:00.851-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-09-07T16:31:03.862-04:00">INTERIM</status_change>
            <status_change date="2007-09-27T08:57:38.656-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 0.9 or earlier is installed">
          <criterion comment="Firefox version 0.9 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:243"/>
          <criterion comment="Mozilla Firefox version 0.9 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:242"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.4 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.4 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:235"/>
          <criterion comment="Mozilla Suite version 1.7.4 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:234"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100049" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla 407 Proxy Information Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0147" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0147"/>
        <description>Firefox before 1.0 and Mozilla before 1.7.5, when configured to use a proxy, respond to 407 proxy auth requests from arbitrary servers, which allows remote attackers to steal NTLM or SPNEGO credentials.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:47:00.000-04:00" comment="Added Firefox, Mozilla as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:240" date="2007-02-12T10:21:00.419-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-12T10:23:02.225-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:241" date="2007-02-12T13:51:00.885-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:232" date="2007-02-12T13:56:00.878-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:233" date="2007-02-12T13:58:00.347-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:34.685-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:234" date="2007-04-23T12:05:00.430-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:05:58.917-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:229" date="2007-04-23T12:05:00.501-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:10:47.226-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 0.9 or earlier is installed">
          <criterion comment="Firefox version 0.9 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:243"/>
          <criterion comment="Mozilla Firefox version 0.9 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:242"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.4 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.4 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:235"/>
          <criterion comment="Mozilla Suite version 1.7.4 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:234"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100048" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Thunderbird Subject to IE Vulnerabilities via javascript</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Mozilla Thunderbird</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0148" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0148"/>
        <description>Thunderbird before 0.9, when running on Windows systems, uses the default handler when processing javascript: links, which invokes Internet Explorer and may expose the Thunderbird user to vulnerabilities in the version of Internet Explorer that is installed on the user's system.  NOTE: since the invocation between multiple products is a common practice, and the vulnerabilities inherent in multi-product interactions are not easily enumerable, this issue might be REJECTED in the future.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:46:00.000-04:00" comment="Added Thunderbird as affected product.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:235." date="2007-01-24T21:18:00.747-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-01-24T21:19:14.166-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:234." date="2007-01-24T21:23:00.750-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-20T13:39:25.007-05:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:231" date="2007-04-23T12:05:00.336-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:08:38.812-04:00">INTERIM</status_change>
            <status_change date="2007-05-09T16:10:46.883-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Thunderbird version 0.8 or earlier is installed">
          <criterion comment="Mozilla Thunderbird version 0.8 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:237"/>
          <criterion comment="Mozilla Thunderbird version 0.8 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:236"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100047" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Mail News Cookie Security Bypass Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0149" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0149"/>
        <description>Thunderbird 0.6 through 0.9 and Mozilla 1.7 through 1.7.3 does not obey the network.cookie.disableCookieForMailNews preference, which could allow remote attackers bypass the user's intended privacy and security policy by using cookies in e-mail messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-01-25T04:03:00.000-04:00" comment="Added Mozilla as affected product.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-01-25T07:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:239." date="2007-01-24T21:21:00.700-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-01-24T21:21:47.803-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:238." date="2007-01-24T21:25:00.771-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:236" date="2007-02-12T13:53:00.146-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:237" date="2007-02-12T13:55:00.760-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:34.281-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:232" date="2007-04-23T12:05:00.713-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:07:02.200-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:233" date="2007-04-23T12:05:00.594-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:10:46.289-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Thunderbird version 0.6-0.9 or earlier is installed">
          <criterion comment="Mozilla Thunderbird version 0.6-0.9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:241"/>
          <criterion comment="Mozilla Thunderbird version 0.6-0.9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:240"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7-1.7.3 is installed">
          <criterion comment="Mozilla Suite version 1.7-1.7.3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:239"/>
          <criterion comment="Mozilla Suite version 1.7-1.7.3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:238"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100046" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Livefeed Bookmark Cookie Swiping</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0150" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0150"/>
        <description>Firefox before 1.0 allows the user to store a (1) javascript: or (2) data: URLs as a Livefeed bookmark, then executes it in the security context of the currently loaded page when the user later accesses the bookmark, which could allow remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:44:00.000-04:00" comment="Added Firefox as affected product.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:240" date="2007-02-12T10:21:00.419-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-12T10:23:01.460-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:241" date="2007-02-12T13:51:00.885-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:33.962-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:234" date="2007-04-23T12:05:00.430-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:05:57.436-04:00">INTERIM</status_change>
            <status_change date="2007-05-09T16:10:45.931-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 0.9 or earlier is installed">
          <criterion comment="Firefox version 0.9 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:243"/>
          <criterion comment="Mozilla Firefox version 0.9 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:242"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100045" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Popup Content Spoofing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1156" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1156"/>
        <description>Mozilla before 1.7.6, and Firefox before 1.0.1, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:43:00.000-04:00" comment="Added Firefox, Mozilla as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:244" date="2007-02-12T09:46:00.841-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-12T09:47:23.547-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:245" date="2007-02-12T09:49:00.289-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:242" date="2007-02-12T10:12:00.118-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:243" date="2007-02-12T10:13:00.712-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:33.532-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:236" date="2007-04-23T11:53:00.689-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:00:30.527-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:235" date="2007-04-23T11:53:00.146-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:10:45.305-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla  Firefox version 1.0 or earlier is installed">
          <criterion comment="Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:245"/>
          <criterion comment="Mozilla Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:244"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.5 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:247"/>
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:246"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100044" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla SSL Lock Image Spoofing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0593" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0593"/>
        <description>Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote attackers to spoof the SSL "secure site" lock icon via (1) a web site that does not finish loading, which shows the lock of the previous site, (2) a non-HTTP server that uses SSL, which causes the lock to be displayed when the SSL handshake is completed, or (3) a URL that generates an HTTP 204 error, which updates the icon and location information but does not change the display of the original site.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:42:00.000-04:00" comment="Added Firefox, Mozilla as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:244" date="2007-02-12T09:46:00.841-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-12T09:47:24.996-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:245" date="2007-02-12T09:49:00.289-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:242" date="2007-02-12T10:12:00.118-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:243" date="2007-02-12T10:13:00.712-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:33.107-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:236" date="2007-04-23T11:53:00.689-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:00:32.385-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:235" date="2007-04-23T11:53:00.146-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:10:44.843-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla  Firefox version 1.0 or earlier is installed">
          <criterion comment="Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:245"/>
          <criterion comment="Mozilla Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:244"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.5 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:247"/>
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:246"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100043" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla UTF8 to Unicode Conversion Heap Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Mozilla Firefox</product>
          <product>Mozilla Thunderbird</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0592" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0592"/>
        <description>Heap-based buffer overflow in the UTF8ToNewUnicode function for Firefox before 1.0.1 and Mozilla before 1.7.6 might allow remote attackers to cause a denial of service (crash) or execute arbitrary code via invalid sequences in a UTF8 encoded string that result in a zero length value.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:41:00.000-04:00" comment="Added Firefox, Mozilla, Thunderbird as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:244" date="2007-02-12T09:46:00.841-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-12T09:47:20.980-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:245" date="2007-02-12T09:49:00.289-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:246" date="2007-02-12T10:04:00.665-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:247" date="2007-02-12T10:07:00.390-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:242" date="2007-02-12T10:12:00.118-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:243" date="2007-02-12T10:13:00.712-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:32.778-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:236" date="2007-04-23T11:53:00.689-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:00:26.838-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:237" date="2007-04-23T11:53:00.235-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in obj:235" date="2007-04-23T11:53:00.146-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:10:44.311-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla  Firefox version 1.0 or earlier is installed">
          <criterion comment="Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:245"/>
          <criterion comment="Mozilla Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:244"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Thunderbird version 1.0 or earlier is installed">
          <criterion comment="Mozilla Thunderbird version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:249"/>
          <criterion comment="Mozilla Thunderbird version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:248"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.5 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:247"/>
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:246"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100042" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Download/Security Dialogs Spoofing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0591" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0591"/>
        <description>Firefox before 1.0.1 allows remote attackers to spoof the (1) security and (2) download modal dialog boxes, which could be used to trick users into executing script or downloading and executing a file, aka "Firespoofing."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-01-31T06:29:00.000-04:00" comment="Updated reference to CVE-2005-0591.  Set product to Mozilla.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <modified date="2006-02-01T05:40:00.000-04:00" comment="Added Firefox to affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:244" date="2007-02-12T09:46:00.841-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-12T09:47:22.898-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:245" date="2007-02-12T09:49:00.289-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:242" date="2007-02-12T10:12:00.118-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:243" date="2007-02-12T10:13:00.712-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:32.517-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:236" date="2007-04-23T11:53:00.689-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:00:29.764-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:235" date="2007-04-23T11:53:00.146-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:10:43.836-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla  Firefox version 1.0 or earlier is installed">
          <criterion comment="Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:245"/>
          <criterion comment="Mozilla Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:244"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.5 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:247"/>
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:246"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100041" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla 'user:pass@host' Spoofing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Mozilla Firefox</product>
          <product>Mozilla Thunderbird</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0590" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0590"/>
        <description>The installation confirmation dialog in Firefox before 1.0.1, Thunderbird before 1.0.1, and Mozilla before 1.7.6 allows remote attackers to use InstallTrigger to spoof the hostname of the host performing the installation via a long "user:pass" sequence in the URL, which appears before the real hostname.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:38:00.000-04:00" comment="Added Firefox, Mozilla, Thunderbird as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:244" date="2007-02-12T09:46:00.841-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-12T09:47:24.354-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:245" date="2007-02-12T09:49:00.289-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:246" date="2007-02-12T10:04:00.665-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:247" date="2007-02-12T10:07:00.390-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:242" date="2007-02-12T10:12:00.118-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:243" date="2007-02-12T10:13:00.712-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:32.236-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:236" date="2007-04-23T11:53:00.689-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:00:31.621-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:237" date="2007-04-23T11:53:00.235-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in obj:235" date="2007-04-23T11:53:00.146-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:10:43.182-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla  Firefox version 1.0 or earlier is installed">
          <criterion comment="Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:245"/>
          <criterion comment="Mozilla Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:244"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Thunderbird version 1.0 or earlier is installed">
          <criterion comment="Mozilla Thunderbird version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:249"/>
          <criterion comment="Mozilla Thunderbird version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:248"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.5 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:247"/>
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:246"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100040" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla String Library Memory Overwrite Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Mozilla Firefox</product>
          <product>Mozilla Thunderbird</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0255" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0255"/>
        <description>String handling functions in Mozilla 1.7.3, Firefox 1.0, and Thunderbird before 1.0.2, such as the nsTSubstring_CharT::Replace function, do not properly check the return values of other functions that resize the string, which allows remote attackers to cause a denial of service and possibly execute arbitrary code by forcing an out-of-memory state that causes a reallocation to fail and return a pointer to a fixed address, which leads to heap corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:37:00.000-04:00" comment="Added Firefox, Mozilla, Thunderbird as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:244" date="2007-02-12T09:46:00.841-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-12T09:47:25.327-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:245" date="2007-02-12T09:49:00.289-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:246" date="2007-02-12T10:04:00.665-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:247" date="2007-02-12T10:07:00.390-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:242" date="2007-02-12T10:12:00.118-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:243" date="2007-02-12T10:13:00.712-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:31.938-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:236" date="2007-04-23T11:53:00.689-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:00:32.674-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:237" date="2007-04-23T11:53:00.235-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in obj:235" date="2007-04-23T11:53:00.146-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:10:42.708-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla  Firefox version 1.0 or earlier is installed">
          <criterion comment="Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:245"/>
          <criterion comment="Mozilla Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:244"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Thunderbird version 1.0 or earlier is installed">
          <criterion comment="Mozilla Thunderbird version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:249"/>
          <criterion comment="Mozilla Thunderbird version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:248"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.5 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:247"/>
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:246"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100039" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Autocomplete Data Leak</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0589" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0589"/>
        <description>The Form Fill feature in Firefox before 1.0.1 allows remote attackers to steal potentially sensitive information via an input control that monitors the values that are generated by the autocomplete capability.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:36:00.000-04:00" comment="Added Firefox as affected product.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:242" date="2007-02-12T10:12:00.118-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-12T10:13:13.856-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:243" date="2007-02-12T10:13:00.712-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:31.699-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:235" date="2007-04-23T11:53:00.146-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:04:16.064-04:00">INTERIM</status_change>
            <status_change date="2007-05-09T16:10:42.216-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla  Firefox version 1.0 or earlier is installed">
          <criterion comment="Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:245"/>
          <criterion comment="Mozilla Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:244"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100038" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla XSLT Stylesheet Information Disclosure Potential</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0588" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0588"/>
        <description>Firefox before 1.0.1 and Mozilla before 1.7.6 does not restrict xsl:include and xsl:import tags in XSLT stylesheets to the current domain, which allows remote attackers to determine the existence of files on the local system.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:35:00.000-04:00" comment="Added Firefox, Mozilla as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:244" date="2007-02-12T09:46:00.841-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-12T09:47:25.815-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:245" date="2007-02-12T09:49:00.289-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:242" date="2007-02-12T10:12:00.118-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:243" date="2007-02-12T10:13:00.712-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:31.445-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:236" date="2007-04-23T11:53:00.689-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:00:33.051-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:235" date="2007-04-23T11:53:00.146-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:10:41.574-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla  Firefox version 1.0 or earlier is installed">
          <criterion comment="Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:245"/>
          <criterion comment="Mozilla Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:244"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.5 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:247"/>
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:246"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100037" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Double Download .lnk Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Mozilla Firefox</product>
          <product>Mozilla Thunderbird</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0587" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0587"/>
        <description>Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote malicious web sites to overwrite arbitrary files by tricking the user into downloading a .LNK (link) file twice, which overwrites the file that was referenced in the first .LNK file.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:34:00.000-04:00" comment="Added Firefox, Mozilla, Thunderbird as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:244" date="2007-02-12T09:46:00.841-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-12T09:47:24.097-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:245" date="2007-02-12T09:49:00.289-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:246" date="2007-02-12T10:04:00.665-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:247" date="2007-02-12T10:07:00.390-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:242" date="2007-02-12T10:12:00.118-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:243" date="2007-02-12T10:13:00.712-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:31.156-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:236" date="2007-04-23T11:53:00.689-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:00:31.242-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:237" date="2007-04-23T11:53:00.235-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in obj:235" date="2007-04-23T11:53:00.146-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:10:40.644-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla  Firefox version 1.0 or earlier is installed">
          <criterion comment="Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:245"/>
          <criterion comment="Mozilla Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:244"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Thunderbird version 1.0 or earlier is installed">
          <criterion comment="Mozilla Thunderbird version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:249"/>
          <criterion comment="Mozilla Thunderbird version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:248"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.5 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:247"/>
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:246"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100036" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla "Save Link As" Dialog Spoofing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0586" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0586"/>
        <description>Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote malicious web sites to spoof the extensions of files to download via the Content-Disposition header, which could be used to trick users into downloading dangerous content.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:33:00.000-04:00" comment="Added Firefox, Mozilla as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:244" date="2007-02-12T09:46:00.841-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-12T09:47:22.609-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:245" date="2007-02-12T09:49:00.289-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:242" date="2007-02-12T10:12:00.118-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:243" date="2007-02-12T10:13:00.712-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:30.783-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:236" date="2007-04-23T11:53:00.689-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:00:29.359-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:235" date="2007-04-23T11:53:00.146-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:10:39.963-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla  Firefox version 1.0 or earlier is installed">
          <criterion comment="Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:245"/>
          <criterion comment="Mozilla Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:244"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.5 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:247"/>
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:246"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100035" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Download Dialog Source Spoofing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0585" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0585"/>
        <description>Firefox before 1.0.1 and Mozilla before 1.7.6 truncates long sub-domains or paths for display, which may allow remote malicious web sites to spoof legitimate sites and facilitate phishing attacks.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:32:00.000-04:00" comment="Added Firefox, Mozilla as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:244" date="2007-02-12T09:46:00.841-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-12T09:47:22.259-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:245" date="2007-02-12T09:49:00.289-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:242" date="2007-02-12T10:12:00.118-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:243" date="2007-02-12T10:13:00.712-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:30.512-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:236" date="2007-04-23T11:53:00.689-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:00:28.959-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:235" date="2007-04-23T11:53:00.146-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:10:39.691-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla  Firefox version 1.0 or earlier is installed">
          <criterion comment="Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:245"/>
          <criterion comment="Mozilla Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:244"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.5 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:247"/>
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:246"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100034" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla HTTP auth Prompt Tab Spoofing</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0584" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0584"/>
        <description>Firefox before 1.0.1 and Mozilla before 1.7.6, when displaying the HTTP Authentication dialog, do not change the focus to the tab that generated the prompt, which could facilitate spoofing and phishing attacks.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:31:00.000-04:00" comment="Added Firefox, Mozilla as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:244" date="2007-02-12T09:46:00.841-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-12T09:47:23.219-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:245" date="2007-02-12T09:49:00.289-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:242" date="2007-02-12T10:12:00.118-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:243" date="2007-02-12T10:13:00.712-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:30.232-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:236" date="2007-04-23T11:53:00.689-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:00:30.135-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:235" date="2007-04-23T11:53:00.146-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:10:39.415-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla  Firefox version 1.0 or earlier is installed">
          <criterion comment="Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:245"/>
          <criterion comment="Mozilla Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:244"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.5 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:247"/>
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:246"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100033" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Image Spoofing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Mozilla Firefox</product>
          <product>Mozilla Thunderbird</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0230" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0230"/>
        <description>Firefox 1.0 does not prevent the user from dragging an executable file to the desktop when it has an image/gif content type but has a dangerous extension such as .bat or .exe, which allows remote attackers to bypass the intended restriction and execute arbitrary commands via malformed GIF files that can still be parsed by the Windows batch file parser, aka "firedragging."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:30:00.000-04:00" comment="Added Firefox, Mozilla, Thunderbird as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:244" date="2007-02-12T09:46:00.841-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-12T09:47:24.611-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:245" date="2007-02-12T09:49:00.289-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:246" date="2007-02-12T10:04:00.665-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:247" date="2007-02-12T10:07:00.390-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:242" date="2007-02-12T10:12:00.118-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:243" date="2007-02-12T10:13:00.712-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:29.812-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:236" date="2007-04-23T11:53:00.689-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:00:31.978-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:237" date="2007-04-23T11:53:00.235-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in obj:235" date="2007-04-23T11:53:00.146-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:10:39.096-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla  Firefox version 1.0 or earlier is installed">
          <criterion comment="Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:245"/>
          <criterion comment="Mozilla Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:244"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Thunderbird version 1.0 or earlier is installed">
          <criterion comment="Mozilla Thunderbird version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:249"/>
          <criterion comment="Mozilla Thunderbird version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:248"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.5 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:247"/>
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:246"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100032" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Cross-site Scripting via Drag and Drop to Tab</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0231" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0231"/>
        <description>Firefox 1.0 does not invoke the Javascript Security Manager when a user drags a javascript: or data: URL to a tab, which allows remote attackers to bypass the security model, aka "firetabbing."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:29:00.000-04:00" comment="Added Firefox, Mozilla as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:244" date="2007-02-12T09:46:00.841-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-12T09:47:21.650-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:245" date="2007-02-12T09:49:00.289-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:242" date="2007-02-12T10:12:00.118-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:243" date="2007-02-12T10:13:00.712-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:29.494-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:236" date="2007-04-23T11:53:00.689-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:00:28.040-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:235" date="2007-04-23T11:53:00.146-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:10:38.802-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla  Firefox version 1.0 or earlier is installed">
          <criterion comment="Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:245"/>
          <criterion comment="Mozilla Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:244"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.5 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:247"/>
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:246"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100031" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Privileged Content Loading Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0527" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0527"/>
        <description>Firefox 1.0 allows remote attackers to execute arbitrary code via plugins that load "privileged content" into frames, as demonstrated using certain XUL events when a user drags a scrollbar two times, aka "Firescrolling."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:27:00.000-04:00" comment="Added Firefox, Mozilla as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:244" date="2007-02-12T09:46:00.841-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-12T09:47:23.803-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:245" date="2007-02-12T09:49:00.289-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:242" date="2007-02-12T10:12:00.118-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:243" date="2007-02-12T10:13:00.712-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:29.119-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:236" date="2007-04-23T11:53:00.689-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:00:30.847-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:235" date="2007-04-23T11:53:00.146-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:10:38.529-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla  Firefox version 1.0 or earlier is installed">
          <criterion comment="Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:245"/>
          <criterion comment="Mozilla Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:244"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.5 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:247"/>
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:246"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100029" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla IDN Homograph Spoofing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0233" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0233"/>
        <description>The International Domain Name (IDN) support in Firefox 1.0, Camino .8.5, and Mozilla before 1.7.6 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T04:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Added CVE #">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-10-05T11:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-26T06:46:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:26:00.000-04:00" comment="Added Firefox, Mozilla as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:244" date="2007-02-12T09:46:00.841-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-12T09:47:21.939-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:245" date="2007-02-12T09:49:00.289-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:242" date="2007-02-12T10:12:00.118-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:243" date="2007-02-12T10:13:00.712-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:28.704-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:236" date="2007-04-23T11:53:00.689-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:00:28.455-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:235" date="2007-04-23T11:53:00.146-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:10:38.131-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla  Firefox version 1.0 or earlier is installed">
          <criterion comment="Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:245"/>
          <criterion comment="Mozilla Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:244"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.5 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:247"/>
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:246"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100028" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla GIF Heap Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Mozilla Firefox</product>
          <product>Mozilla Thunderbird</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0399" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0399"/>
        <description>Heap-based buffer overflow in GIF2.cpp in Firefox before 1.0.2, Mozilla before to 1.7.6, and Thunderbird before 1.0.2, and possibly other applications that use the same library, allows remote attackers to execute arbitrary code via a GIF image with a crafted Netscape extension 2 block and buffer size.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:25:00.000-04:00" comment="Added Firefox, Mozilla, Thunderbird as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added anchors to regex in ste:249" date="2007-02-12T09:11:00.072-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-12T09:12:24.143-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:248" date="2007-02-12T09:44:00.175-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:244" date="2007-02-12T09:46:00.841-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:245" date="2007-02-12T09:49:00.289-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:246" date="2007-02-12T10:04:00.665-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:247" date="2007-02-12T10:07:00.390-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:28.296-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:238" date="2007-04-23T11:53:00.399-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T11:58:57.812-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:236" date="2007-04-23T11:53:00.689-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in obj:237" date="2007-04-23T11:53:00.235-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:10:37.801-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.1 or earlier is installed">
          <criterion comment="Firefox version 1.0.1 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:251"/>
          <criterion comment="Mozilla Firefox version 1.0.1 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:250"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Thunderbird version 1.0 or earlier is installed">
          <criterion comment="Mozilla Thunderbird version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:249"/>
          <criterion comment="Mozilla Thunderbird version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:248"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.5 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:247"/>
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:246"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100027" version="5" class="vulnerability">
      <metadata>
        <title>Firefox Sidebar Panel Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0402" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0402"/>
        <description>Firefox before 1.0.2 allows remote attackers to execute arbitrary code by tricking a user into saving a page as a Firefox sidebar panel, then using the sidebar panel to inject Javascript into a privileged page.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:23:00.000-04:00" comment="Added Firefox as affected product.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added anchors to regex in ste:249" date="2007-02-12T09:11:00.072-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-12T09:12:24.635-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:248" date="2007-02-12T09:44:00.175-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:28.026-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:238" date="2007-04-23T11:53:00.399-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T11:58:58.145-04:00">INTERIM</status_change>
            <status_change date="2007-05-09T16:10:37.557-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.1 or earlier is installed">
          <criterion comment="Firefox version 1.0.1 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:251"/>
          <criterion comment="Mozilla Firefox version 1.0.1 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:250"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100026" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla XUL Drag and Drop Security Bypass Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0401" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0401"/>
        <description>FireFox 1.0.1 and Mozilla before 1.7.6 do not sufficiently address all attack vectors for loading chrome files and hijacking drag and drop events, which allows remote attackers to execute arbitrary XUL code by tricking a user into dragging a scrollbar, a variant of CVE-2005-0527, aka "Firescrolling 2."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:22:00.000-04:00" comment="Added Firefox, Mozilla as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added anchors to regex in ste:249" date="2007-02-12T09:11:00.072-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-12T09:12:22.583-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:250" date="2007-02-12T09:24:00.965-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:251" date="2007-02-12T09:28:00.417-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:248" date="2007-02-12T09:44:00.175-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:27.519-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:239" date="2007-04-23T11:53:00.596-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T11:56:17.437-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:238" date="2007-04-23T11:53:00.399-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:10:37.223-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.1 or earlier is installed">
          <criterion comment="Firefox version 1.0.1 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:251"/>
          <criterion comment="Mozilla Firefox version 1.0.1 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:250"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.6 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:253"/>
          <criterion comment="Mozilla Suite version 1.7.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:252"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100025" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Javascript "lambda"</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0989" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0989"/>
        <description>The find_replen function in jsstr.c in the Javascript engine for Mozilla Suite 1.7.6, Firefox 1.0.1 and 1.0.2, and Netscape 7.2 allows remote attackers to read portions of heap memory in a Javascript string via the lambda replace method.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <modified date="2005-10-11T04:20:00.000-04:00" comment="modified wrt-10045 - Removed doubled backslash from string literal test.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2005-10-26T06:46:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:20:00.000-04:00" comment="Added Firefox, Mozilla as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:250" date="2007-02-12T09:24:00.965-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-12T09:25:33.912-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:251" date="2007-02-12T09:28:00.417-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:256" date="2007-02-12T09:40:00.863-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:257" date="2007-02-12T09:43:00.244-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:27.212-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:239" date="2007-04-23T11:53:00.596-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T11:56:19.342-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:243" date="2007-04-23T11:53:00.469-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:10:36.906-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.2 or earlier is installed">
          <criterion comment="Firefox version 1.0.2 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:259"/>
          <criterion comment="Mozilla Firefox version 1.0.2 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:258"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.6 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:253"/>
          <criterion comment="Mozilla Suite version 1.7.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:252"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100024" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla PLUGINSPAGE Privileged Javascript Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0752" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0752"/>
        <description>The Plugin Finder Service (PFS) in Firefox before 1.0.3 allows remote attackers to execute arbitrary code via a javascript: URL in the PLUGINSPAGE attribute of an EMBED tag.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <modified date="2005-10-11T04:20:00.000-04:00" comment="modified wrt-10045 - Removed doubled backslash from string literal test.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2005-10-26T06:46:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:19:00.000-04:00" comment="Added Firefox as affected product.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:256" date="2007-02-12T09:40:00.863-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-12T09:41:37.932-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:257" date="2007-02-12T09:43:00.244-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:26.864-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:243" date="2007-04-23T11:53:00.469-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T11:57:34.505-04:00">INTERIM</status_change>
            <status_change date="2007-05-09T16:10:36.639-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.2 or earlier is installed">
          <criterion comment="Firefox version 1.0.2 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:259"/>
          <criterion comment="Mozilla Firefox version 1.0.2 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:258"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100023" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla blocked javascript: popup Privilege Escalation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1153" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1153"/>
        <description>Firefox before 1.0.3 and Mozilla Suite before 1.7.7, when blocking a popup, allows remote attackers to execute arbitrary code via a javascript: URL that is executed when the user selects the "Show javascript" option.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <modified date="2005-10-11T04:20:00.000-04:00" comment="modified wrt-10045 - Removed doubled backslash from string literal test.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <modified date="2005-10-11T04:51:00.000-04:00" comment="modified wrt-10049 - Removed doubled backslash from string literal test.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2005-10-26T06:46:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:18:00.000-04:00" comment="Added Firefox, Mozilla as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:250" date="2007-02-12T09:24:00.965-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-12T09:25:32.807-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:251" date="2007-02-12T09:28:00.417-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:256" date="2007-02-12T09:40:00.863-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:257" date="2007-02-12T09:43:00.244-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:26.534-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:239" date="2007-04-23T11:53:00.596-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T11:56:17.901-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:243" date="2007-04-23T11:53:00.469-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:10:36.192-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.2 or earlier is installed">
          <criterion comment="Firefox version 1.0.2 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:259"/>
          <criterion comment="Mozilla Firefox version 1.0.2 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:258"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.6 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:253"/>
          <criterion comment="Mozilla Suite version 1.7.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:252"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100022" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Global Pollution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1154" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1154"/>
        <description>Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to execute arbitrary script in other domains via a setter function for a variable in the target domain, which is executed when the user visits that domain, aka "Cross-site scripting through global scope pollution."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <modified date="2005-10-11T04:20:00.000-04:00" comment="modified wrt-10045 - Removed doubled backslash from string literal test.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2005-10-26T06:46:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:17:00.000-04:00" comment="Added Firefox, Mozilla as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:250" date="2007-02-12T09:24:00.965-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-12T09:25:34.209-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:251" date="2007-02-12T09:28:00.417-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:256" date="2007-02-12T09:40:00.863-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:257" date="2007-02-12T09:43:00.244-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:26.212-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:239" date="2007-04-23T11:53:00.596-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T11:56:19.806-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:243" date="2007-04-23T11:53:00.469-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:10:35.815-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.2 or earlier is installed">
          <criterion comment="Firefox version 1.0.2 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:259"/>
          <criterion comment="Mozilla Firefox version 1.0.2 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:258"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.6 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:253"/>
          <criterion comment="Mozilla Suite version 1.7.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:252"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100021" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla favicons Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1155" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1155"/>
        <description>The favicon functionality in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to execute arbitrary code via a &lt;LINK rel="icon"> tag with a javascript: URL in the href attribute, aka "Firelinking."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <modified date="2005-10-11T04:20:00.000-04:00" comment="modified wrt-10045 - Removed doubled backslash from string literal test.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2005-10-26T06:46:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:16:00.000-04:00" comment="Added Firefox, Mozilla as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:250" date="2007-02-12T09:24:00.965-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-12T09:25:33.495-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:251" date="2007-02-12T09:28:00.417-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:256" date="2007-02-12T09:40:00.863-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:257" date="2007-02-12T09:43:00.244-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:25.895-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:239" date="2007-04-23T11:53:00.596-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T11:56:18.881-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:243" date="2007-04-23T11:53:00.469-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:10:35.364-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.2 or earlier is installed">
          <criterion comment="Firefox version 1.0.2 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:259"/>
          <criterion comment="Mozilla Firefox version 1.0.2 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:258"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.6 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:253"/>
          <criterion comment="Mozilla Suite version 1.7.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:252"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100020" version="5" class="vulnerability">
      <metadata>
        <title>Mozilla Search Plugin Cross-site Scripting Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1156" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1156"/>
        <description>Firefox before 1.0.3, Mozilla Suite before 1.7.7, and Netscape 7.2 allows remote attackers to execute arbitrary script and code via a new search plugin using sidebar.addSearchEngine, aka "Firesearching 1."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <modified date="2005-10-11T04:20:00.000-04:00" comment="modified wrt-10045 - Removed doubled backslash from string literal test.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2005-10-26T06:46:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:14:00.000-04:00" comment="Added Firefox and Mozilla as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:250" date="2007-02-12T09:24:00.965-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-12T09:25:32.117-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:251" date="2007-02-12T09:28:00.417-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:256" date="2007-02-12T09:40:00.863-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified comment="Added anchor to regex in ste:257" date="2007-02-12T09:43:00.244-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:25.521-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:239" date="2007-04-23T11:53:00.596-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T11:56:16.826-04:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in obj:243" date="2007-04-23T11:53:00.469-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-09T16:10:34.914-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.2 or earlier is installed">
          <criterion comment="Firefox version 1.0.2 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:259"/>
          <criterion comment="Mozilla Firefox version 1.0.2 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:258"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.6 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:253"/>
          <criterion comment="Mozilla Suite version 1.7.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:252"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100019" version="5" class="vulnerability">
      <metadata>
        <title>Firefox Sidebar Code Execution via _search Target</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Mozilla Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1158" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1158"/>
        <description>Multiple "missing security checks" in Firefox before 1.0.3 allow remote attackers to inject arbitrary Javascript into privileged pages using the _search target of the Firefox sidebar.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <modified date="2005-10-11T04:20:00.000-04:00" comment="modified wrt-10045 - Removed doubled backslash from string literal test.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2005-10-26T06:46:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:12:00.000-04:00" comment="Added Firefox as affected product.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in ste:256" date="2007-02-12T09:40:00.863-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-02-12T09:41:39.399-05:00">INTERIM</status_change>
            <modified comment="Added anchor to regex in ste:257" date="2007-02-12T09:43:00.244-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:25.269-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:243" date="2007-04-23T11:53:00.469-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T11:57:35.930-04:00">INTERIM</status_change>
            <status_change date="2007-05-09T16:10:34.518-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.2 or earlier is installed">
          <criterion comment="Firefox version 1.0.2 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:259"/>
          <criterion comment="Mozi